• Zak@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    Sure, the developer needs to keep the certificate up to date and re-sign the APK on occasion.

    • Kairos@lemmy.today
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 months ago

      So any APK I download will just expire at some point in time that’s probably really annoying to know, and then I have to dig through the internet again so I can install the app again?

      • Pycorax@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        If it’s anything like how Windows does it, you would still be able to override it. It just gives you a scary warning and hides the option unless you click “more info” or something.

      • Zak@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 months ago

        Another option is to allow otherwise-valid signatures after expiration. It’s generally still possible to check them.

          • Zak@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            How? Expiration doesn’t grant an unauthorized party access to the private key.