apk validation by file size

by Lee » Mon, 07 Sep 2009 23:24:54 GMT


Sponsored Links
 I had the thought of checking for tampering with the apk by embedding
a couple of checks against it's size once installed on  the
device.

I was just a bit concerned that maybe the size would change dependent
on the device (e.g. different FS format or whatever).

Thanks,

Lee

p.s. no debates about whether this is worthwhile or not please :-)
--~--~---------~--~----~------------~-------~--~----~



apk validation by file size

by Dianne Hackborn » Tue, 08 Sep 2009 02:51:09 GMT


 The best way is to check the certificate it is signed with, since nobody can
sign with a certificate that they haven't been given the private key for.
That said, if they have tampered with your .apk, they can also tamper with
your code, and change whatever check you may have.






-- 
Dianne Hackborn
Android framework engineer
hack...@android.com

Note: please don't send private questions to me, as I don't have time to
provide private support, and so won't reply to such e-mails.  All such
questions should be posted on public forums, where I and others can see and
answer them.

--~--~---------~--~----~------------~-------~--~----~


Sponsored Links


apk validation by file size

by Lee » Tue, 08 Sep 2009 03:49:27 GMT


 > The best way is to check the certificate it is signed with, since nobody can

Is there system code that I can call for that ? Any keywords you could
throw in ?

My original question, is the APK size the same on any device once
created ?

Thanks again,

Lee
--~--~---------~--~----~------------~-------~--~----~



apk validation by file size

by Mark Murphy » Tue, 08 Sep 2009 04:16:56 GMT


 


PackageManager#getPackageInfo() returns a PackageInfo which has a
signatures field.


I don't think you have any supported means of figuring out the size of
the APK on the device.

-- 
Mark Murphy (a Commons Guy)
 http://commonsware.com  |  http://twitter.com/commonsguy 

Warescription: Three Android Books, Plus Updates, $35/Year

--~--~---------~--~----~------------~-------~--~----~



apk validation by file size

by Lee » Tue, 08 Sep 2009 15:11:21 GMT


 > PackageManager#getPackageInfo() returns a PackageInfo which has a

Thanks Mark, should've thought of PackageInfo ahem.


Well the thing is just lying around in the file system, it's easy to
test it's size.

Lee
--~--~---------~--~----~------------~-------~--~----~



Other Threads

1. Moto Droid 2nd & New

Malam semua , numpang lapak yah ...

Moto Droid 2nd ;
- Kondisi istimewa terawat 
- Mesin normal 100%
- Fullset (hh charger dus sdcard 16gb)
- Rooted + Froyo
- Terinjek nomer cantik Smart
- Pulsa 65rb (bisa buat inet bbrp minggu)
@ 3,3juta net include ongkir ,lokasi bandung.

Juga tersedia yang New @3,9juta nett.

Japri : ary.ma...@ymail.com / 08122 1111 191.

Thank's mods & rr buat jalum nya.

Ary Malik , i-gadget.

-- 
"Indonesian Android Community [id-android]" 

2. Android developer in Brazil

Hi!

    Im a software developer and I couldn't be out of this so
important platform. I have an android aplicattion developed totally by
me and I have too much to contribute and many questions to do.

-- 

3. Can load html from assets but loading JS, CSS from within that HTML is another story ...

4. Calculating Hash Value

5. CTS install_failed_insufficient_storage error

6. How to do occur hardware keyboard event using software keyboard

7. iPhone , Android and Mobile Web, Making friends and looking for coorperation