Fake Sig Protection
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 14.6k
- Forks
- 3.2k
- Avg merge
- 12d 11h
- Merged PRs (30d)
- 4
Description
Am I correct that any app can take advantage of the fake sig support if it is compiled into a rom ? How hard would it be for the patches to be modified to require microg to be signed with a key held by the rom builder ? Would this fully protect from a malicious app doing bad stuff using fake sig support ?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or entry points are named. Start by tracing the existing fake signature support and its ROM integration, then assess how requiring microG to use a ROM-builder-held signing key would affect malicious apps. Done means documenting whether the proposed signing restriction is feasible and whether it prevents the abuse described.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- android, java
- Domain
- mobile, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100