I am developing an android app which is talking with a server, and I want to verify at run time that my app has not been modified since I released it(a user with a modified app should not be able to login to app).
Since modified app's signature is different from the original signature, I decided to :
- Extract signing certificate/s which is embedded in the android app
- send it to the server with the login request (Coding the whole verification process in client side(i.e. apk) does not work as someone could modify the apk to bypass it.)
- verify it
- if certificate is valid process login request / else return error
This is my code for number 1 above :
Context context = this;
PackageManager pm = context.getPackageManager();
String packageName = context.getPackageName();
int flags = PackageManager.GET_SIGNATURES;
PackageInfo packageInfo = null;
try {
packageInfo = pm.getPackageInfo(packageName, flags);
} catch (PackageManager.NameNotFoundException e) {
e.printStackTrace();
}
Signature[] signatures = packageInfo.signatures;
So my questions are :
- Is there a better way to verify an apk?
- If this method is okay,
2.1 Would sending a certificate cost high in bandwidth?
2.2 How can I verify the certificate?(I have mykey.jks at server side which I originally used to sign the apk)
(Also this is my first ever question on stackoverflow, so pointing out any mistakes I did in asking the question are highly appreciated!. )