switch the Updater app to the RecoverySystem API for verifying downloads #158

Closed
thestinger opened this Issue Jan 30, 2016 · 1 comment

Comments

Projects
None yet
1 participant
@thestinger
Contributor

thestinger commented Jan 30, 2016

The signatures are already verified by the recovery itself so it's not a security issue, but it's potentially a usability issue since the recovery can't do much in terms of error handling other than booting back into the operating system. The updater seems like it might already be able to do verification itself, but it should be switched to the AOSP API since that's going to be more robust and will cut down on the complexity.

@thestinger

This comment has been minimized.

Show comment Hide comment
@thestinger

thestinger Nov 29, 2016

Contributor

This is now implemented.

Contributor

thestinger commented Nov 29, 2016

This is now implemented.

@thestinger thestinger closed this Nov 29, 2016

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment