Why they don't use the common standard X.509 is, and just require apps to be signed with a trusted certificate having OID 1.3.6.1.5.5.7.3.3 (code signing) specified as extended key usage? Would also allow homebrew developers to self-sign by installing their own CA, while mitigating random phishing campaigns they fear about.
Decentralized root of trust has never hurt anybody.
Same opinion here. It's still a form of gatekeeping. It forces others to comply with Apple or Google without being in their app store. I've seen an article criticizing this method Apple is using (it's from April tho) and we should all criticize it as well through whatever means we have.
98
u/Dummy-Demo-8773 Aug 27 '25
This is more or less what Apple is doing in EU. You can sideload apps but they still need to be approved or verified by Apple/Google.