Hacker News new | past | comments | ask | show | jobs | submit login

Verifying the software one is running is not absolutism. Just because one cannot provide 'perfect' security isn't a reason to give up trying to provide some security by elevating the effort requires to conduct an attack. That locks can be picked isn't an excuse to not bother locking the door.



You'll note that logically a company cannot actually solve this problem themselves in a satisfactory way, since you would have the same problem trusting the verification mechanism as you did trusting their app in the first place.

What you want belongs as an operating system or app distribution mechanism concern. A third party OS extension might make sense. Even that's a bit fraught if there is any kind of dynamic code execution (aka code that appears at runtime, say, a web view).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: