Can we feed SHA256 fingerprints into #obtanium to verify downloaded apks?

Reply to this note

Please Login to reply.

Discussion

Ideally, on mobile:

- download apk

- verify download

- point #obtanium to downloaded, verified file

I feel this would require developers to post sha256 in repos. Otherwise how would you know you didn't get a fake apk with its own sha256 not knowing the difference?