microg / microg/GmsCore

Fake Sig Protection

Open
#243 10 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Java
Stars
14.6k
Forks
3.2k
Avg merge
12d 11h
Merged PRs (30d)
4

Description

Am I correct that any app can take advantage of the fake sig support if it is compiled into a rom ? How hard would it be for the patches to be modified to require microg to be signed with a key held by the rom builder ? Would this fully protect from a malicious app doing bad stuff using fake sig support ?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or entry points are named. Start by tracing the existing fake signature support and its ROM integration, then assess how requiring microG to use a ROM-builder-held signing key would affect malicious apps. Done means documenting whether the proposed signing restriction is feasible and whether it prevents the abuse described.

Written by the indexing model from the issue text.

Assessment

Tech stack
android, java
Domain
mobile, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.