Google now offers an app signing service via Google Play. This promises to help app developers and administrators if they ever lose their key, or discover it has been compromised.
Security issues, somewhat fixed
Until now, losing a key meant devs could not update their published apps. Even worse, a compromised app key would mean that someone else could maliciously use the permissions.
Now, with the latest tweaks to the Google Play Console, these issues should become less of a hassle.
Managing signatures
In the developers’ Google Play Console, ‘App signing’ is now available via the ‘Release Management’ tools.
For new apps, devs can get Google Play to generate the signing key. In this case, Google manages just about everything.
For existing apps, certificates and keys need to be uploaded before enrolling. There is a wizard-like process to make it easy, including instructions for devs who use a Java KeyStore or encrypt their keys via plaintext PEM files.
They’re also offering a web support form that will allow developers to revoke a key and generate a new one.
To get more technical
There’s a bunch more detail on app signing keys in the Android Developer official documentation.
Given recent product tweaks and recent press, are you becoming more concerned with security issues on Google and Android, or less concerned?
Copy Transmission is a Melbourne-based agency :: Better Brands. Loud & Clear.






















RECOMMENDED FOR YOU
Google’s AI Answers Are Creating Brand Reputation Problems
Google’s AI search products are creating a new reputation…
Google’s AI search products are creating a new reputation…
Google Boosts Reporting AI In GA4 & Google Ads
Google is bringing Gemini much deeper into Google Ads…
Google is bringing Gemini much deeper into Google Ads…
Google Pushes Search Ads Into AI Max
Google is moving paid search further away from the…
Google is moving paid search further away from the…