I would like to force close my app and open my app's official Play Store page if it was installed from a third party app store.
The idea would be that I simply check the last five characters of my key signature runtime with this code:
public static String getSpecHashSuffix(Context ctx) {
String hash = "";
String ret = "";
try {
PackageInfo info = ctx.getPackageManager().getPackageInfo(ctx.getPackageName(), PackageManager.GET_SIGNATURES);
for (Signature signature : info.signatures) {
MessageDigest md = MessageDigest.getInstance("SHA");
md.update(signature.toByteArray());
//removing spec characters
hash = Base64.encodeToString(md.digest(), Base64.DEFAULT).replaceAll("/", "").replaceAll("=", "").replaceAll("\\+", "");
//removing numbers
hash = hash.replaceAll("\\d", "");
//removing new lines
hash = hash.replaceAll("\n", "");
//lowercasing
hash = hash.toLowerCase();
ret = "" + hash.charAt(hash.length() - 5) + hash.charAt(hash.length() - 4) + hash.charAt(hash.length() - 3) + hash.charAt(hash.length() - 2) + hash.charAt(hash.length() - 1);
}
} catch (Exception e) {
e.printStackTrace();
}
return ret;
}
The returned String is something like this: "abcde".
I would simply check this String against a constant in the code with the very same value.
If they are not the same, I would force close the app and open the app's official Play Store page with an intent.