Are Android apps signed like Windows executables. If so, I would like to see a "trusted software vendors" list added to CMS.
Knowing how CIS works, I feel a little unsafe that a rogue app "may" make it onto my phone and CMS's antivirus database will not be aware of it.
