LINE Jan 29, 2019

AIR GO and APK Signing

Article Summary

Seunghoon Kim from LINE's AIR GO team breaks down Android's APK signing evolution. If you're still using v1 signing, you're leaving security holes wide open.

This deep dive from LINE's security team explains how Android's APK signing schemes evolved from v1 (JAR signing) through v2 and v3, which introduced proof-of-rotation for key management. The article covers the technical architecture of each scheme and how AIR GO detects signing vulnerabilities.

Key Takeaways

Critical Insight

Android's v3 signing scheme solves the critical problem of lost signing keys by allowing developers to rotate certificates while maintaining app update capability on Google Play.

The article includes modified 010 Editor templates that visualize the invisible APK Signing Block that standard ZIP tools can't detect.

Recent from LINE

Related Articles