Commentary: Google's promise should push competing brands to step up, making more phones safer to use for the long haul. Mike Sorrentino is a Senior Editor for Mobile, covering phones, texting apps ...
So the problem is, that some software is downloading unsigned (or not verifying) signatures on their updates. That is NOT best practice. Never trust what you download. Even a signed file of versions ...