upvote
> but almost apps on Google Play are now signed by Google (with keys either generated by them or provided to them),

Yes! Google's goddamn "bundles" seem to be enforced to everybody. I guess part of Google "not being evil" and all. Another reason why initiatives like EU's Digital Markets Act are needed, I guess.

And yet another reason to use GrapheneOS, of course.

> If you mean Accrescent, it only checks the app's signature, not the hash of the individual versions.

No, there is an app called "AppVerifier" actually. That's the one I meant.

reply
> No, there is an app called "AppVerifier" actually. That's the one I mean

https://github.com/soupslurpr/AppVerifier , right? It only checks the signature (the certificate)

> And yet another reason to use GrapheneOS, of course.

Which always recommended to use the Play Store, though

reply