On Sat, Jan 21, 2012 at 9:14 AM, Put_tiMe <[email protected]> wrote:
> Does signature-level permission  mean that the app should be signed by
> Google (or the OEM) saying that it can delete cache files?

It means that the app needs to be signed by the same signing key as
signed the firmware for the device that it is running on.

BTW, from what I can tell, these apps cannot clear individual app's
caches (except on rooted devices), but they are exploiting what I
consider to be a security hole for other cache-clearing scenarios. I
am working up a demonstration app now to file with Android Security.

-- 
Mark Murphy (a Commons Guy)
http://commonsware.com | http://github.com/commonsguy
http://commonsware.com/blog | http://twitter.com/commonsguy

_The Busy Coder's Guide to *Advanced* Android Development_ Version 2.3
Available!

-- 
You received this message because you are subscribed to the Google
Groups "Android Developers" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to
[email protected]
For more options, visit this group at
http://groups.google.com/group/android-developers?hl=en

Reply via email to