AppVerifier icon indicating copy to clipboard operation
AppVerifier copied to clipboard

Support for verifying Google Play security metadata

Open kasia-de opened this issue 10 months ago • 2 comments

https://android-developers.googleblog.com/2018/06/google-play-security-metadata-and.html

Request:

Could AppVerifier verify Google Play security metadata?

Rationale:

AppVerifier verifying the Google Play security metadata will allow people to use untrusted sources where APKs are redistributed, such as apkmirror.com and others, while ensuring the integrity and root of trust of obtained applications.

Google Play security metadata is verified offline by the Google Play Store Android application, and the metadata is kept intact when transferring the apks, or backing them up from a device. It is written by on the Android Developers Blog, that the "metadata addition" is "inserted into the APK Signing Block."

Time cost:

It seems to me that this could be possiible, potentially requiring at most some reverse engineering of the Google Play Store application, or analysis of the signing blocks of APKs served by the Google Play Store.

kasia-de avatar Feb 16 '25 02:02 kasia-de

https://android.googlesource.com/platform/frameworks/base/+/master/core/java/android/util/apk/SourceStampVerifier.java

soupslurpr avatar Feb 16 '25 02:02 soupslurpr

I would greatly appreciate that feature - that we can at least be sure to have the same APKs like Google Play distributes (without having to share all of our data with Google).

qdrop17 avatar Oct 13 '25 14:10 qdrop17