Hi,

I know the word *"different" *is little bit controversial in the title 
because I am using same package name in both applications but both 
applications have different signing certificates. I know that package name 
has to be different if I want them to be treated different. 

What I am not able to figure out is that why android assigns same UID to 
another application if it has the same package name of prior application 
but signed from different certificate. Is there any role certificates plays 
in the assignment of UID to application. If not then this will result in a 
security flaw because a hacker can see the secret items from keystore of an 
application if he install his malware application with same package name 
even if it is signed from different certificate (Installation of malware 
application requires deletion of actual app).

Thanks,

Noor

-- 
You received this message because you are subscribed to the Google
Groups "Android Developers" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to
[email protected]
For more options, visit this group at
http://groups.google.com/group/android-developers?hl=en

Reply via email to