So any APK I download will just expire at some point in time that’s probably really annoying to know, and then I have to dig through the internet again so I can install the app again?
If it’s anything like how Windows does it, you would still be able to override it. It just gives you a scary warning and hides the option unless you click “more info” or something.
So any APK I download will just expire at some point in time that’s probably really annoying to know, and then I have to dig through the internet again so I can install the app again?
If it’s anything like how Windows does it, you would still be able to override it. It just gives you a scary warning and hides the option unless you click “more info” or something.
Another option is to allow otherwise-valid signatures after expiration. It’s generally still possible to check them.
That completely nullifies the entire point of signature validations.
How? Expiration doesn’t grant an unauthorized party access to the private key.
There’s zero cryptographic reason to have a signed date at that point.