QUOTE(xander2k8 @ Apr 26 2023, 05:47 PM)
If the user update through non official means or using non authorised apk it can be phished easily as it has already been proven already π€¦ββοΈ and it is not misinformation as it is proven fact otherwise why would certains apps use OTC to authenticate transactions π€¦ββοΈ
That is why you logged out after you use your account particularly with those which financially sensitive which is why some apps will have either log out or timeout on the app itself π€¦ββοΈ
He already mentioned the user went through the playstore. for official playstore or official repos, this is usually what happens in an update:
1) checks whether any new packages present
2) downloads from the repositories (in this case the playstore)
3) verifies the checksum of the downloaded package
4) writes over the changed files, user configuration files may or may not be overwritten
All this is done on the phone. In a normal update process, it doesn't send user info out from the phone. (edit: beyond general stuff like OS versions, compatibility etc)
Any data breach for a tampered installation file will usually happen after installation, when the user next logs in and uses the app.
TLDR: it really doesn't matter if you sign out or not before you update your apps.
This post has been edited by loserguy: Apr 26 2023, 05:59 PM