Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It offers a fingerprint you're supposed to validate over sneakernet but people are lazy


and Google Play offers the possibility to distribute an update only to specific e-mail addresses, so if there is a need to compromise users with a malicious update that shows another fingerprint it's really doable (or just copy the messages, like Skype was doing with TOM-Skype).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: