Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The question is - how do you intend to verify whether an application is official or unofficial? What's stopping the official application to be 'patched' with a fake signature feigning validity?


Asymmetric cryptography?


How? If you're validating a server, sure. But a server validating a client?

Anything you ship with the app can be extracted.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: