177
edits
Changes
m
→Debian Keyring (Package Management) for distribution of apps
*# compromise the keys (developer *and* FTP master) signing the app (assuming you require app updates to be signed with the same key)
*# compromise or trigger the update mechanism for the app
*# wait for updates to trickle outwithout anyone noticing the previous steps.
==== dealing with rogue applications ====