I see devs sign their apps in 2 way:
- they sign a hash of the apk, zip etc
- or thr sign directly de apk, zip etc
What is the difference? Why choosing doing an extra step and hashing it first?
I see devs sign their apps in 2 way:
- they sign a hash of the apk, zip etc
- or thr sign directly de apk, zip etc
What is the difference? Why choosing doing an extra step and hashing it first?
By signing the hash it's obvious they and only they acknowledge the .apk, .zip? Am I stupid?
If I could rephrase my Q would be:
- if its good enough to sign the apk/zip, why signing a hash? Isnt it an extra step?
Si solo firmas apk o zip la verificación necesita saber manejar gnupg. El hash serÃa más user friendly, entiendo. Y se firma el hash para mayor garantÃa. Eso se me ocurre.
Exacto el SO operativo anfitrión dónde será instalado el APK deberá tener el mecanismo de reconocer esa firma como válida y permitir la instalación, o en su lugar informar que contiene o no una firma inválida. En el caso del hash como lo has dicho serÃa para validar la autenticidad de lo descargado y que es bit a bit igual al origen