@Benking what would actually fix this, signature verification surfaced inside the store listing itself, or people learning to check a hash before they install? a year of warnings from the sparrow developer and the fake was still ranking, so the gatekeeper model is not the safeguard people assume it is.