Hacker Read top | best | new | newcomments | leaders | about | bookmarklet login

Right, and your device knows it came from the app store because of code signing.


sort by: page size:

Most apps are signed nowadays, regardless of whether or not you're getting them from the store.

Same with an app that is uploaded to the iOS App Store.

...if the app arrived on the device from the app store.

> Let’s say you take your app down, but someone uploads it to other app stores.

Then it would be your Apple Developer Account signing it right?


Apps are signed.

And is, again, instantly revokable. It'll be annoying if it's stolen, but you just revoke it, give the company the new one, and update the app in the app store (or your download, if you're not in the store). This is arguably far better than being unknowingly hit by malware.

That's not new though, Apple is the one signing the apps on the store from its launch.

Correct but if your not on the app store, who will know about your app.

But isn't apple store already re-sign applications code with apple's own key so they can do stuff like this? Or is it only on iOS?

But they do depend on Apple's signing of the app before installation on the phone, right?

I'm not sure if this applies to Xcode, but at least with Coda, even if you purchase it outside the App Store, it has an 'Installed' label and presumably gets updated through the App Store as well.

You don't need to be in the App Store, you just need a signed developer certificate (99 USD/year).

How does this work, being able to be downloaded from the app store and all?

I signed up and got sent out a code to download the app from the app store.

Thanks. I guess this makes sense: I can migrate from the App Store later if I'd want to.

You can still self-sign your apps.

Because iOS apps talk to the Notarisation Service on launch.

So they know total app installs as well as the installs purchased from the App Store.


Obviously you use your vendor's "app store".

The only reason I say this is because it appears it does actually have to download back onto your device. So I'm not totally sure.
next

Legal | privacy