logoalt Hacker News

array_key_firsttoday at 1:21 AM1 replyview on HN

Except the Play Store is a hot mess, and Google does little to no review of apps. Trusted repositories work best when the repository maintainers build and read the code themselves, like on f-droid or Debian. What Google and Apple are doing with their respective stores is security theater. I would not be surprised if they don't even run the app.


Replies

ajrosstoday at 2:37 AM

Again though, that's mixing things up. The question is whether or not mitigating the exploit requires an OS patch be applied promptly.

And it seems like it doesn't. If there is a live exploit in the wild (as seems to be contended), then clearly the solution is to blacklist the app (if it exists on the store, which is not attested) and pull it off the store. And that will work regardless of whether or not Samsung got an update out. Nor does it require an "audit" process in the store, the security people get to short circuit that stuff.