Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you install from an App store and want to know if it matches the source, you need to pull the installed package from your phone and compare the contents to your own known good binaries.

Ideally, if the builds are fully repeatable, the only differences should be in the signatures, but of course, you need to confirm that the signature doesn't drive unexpected differences in behavior.

I don't have the skills or the tools to do this, but it's not like it's some impossible mystery.



In order to do what you’re suggesting you have to jailbreak a device, which I mentioned in my comment and is discussed in many blog posts such as [0], which links to others.

Without a jailbreak, which isn’t a sure thing and even if available is not nearly as feasible as sideloading, it in fact is an impossible mystery to decrypt an iOS app store build to inspect it.

[0]: https://ivrodriguez.com/reverse-engineer-ios-apps-ios-11-edi...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: