# Is it necessary to verify the GPG signature of an app installed from the web on macOS?

**URL:** https://discuss.privacyguides.net/t/is-it-necessary-to-verify-the-gpg-signature-of-an-app-installed-from-the-web-on-macos/22754
**Category:** Questions
**Created:** 2024-11-26T17:07:32Z
**Posts:** 7

## Post 1 by @anon94009837 — 2024-11-26T17:07:32Z

Or does something like notarization take care of that?

---

## Post 2 by @fria — 2024-11-26T17:22:37Z

You’re basically trusting Apple that it’s the right dev.

---

## Post 3 by @anon94009837 — 2024-11-26T17:24:09Z

Wouldn’t that be the case if I’m installing from the App Store as well? If it’s the same then I have no problem trusting Apple with this.

---

## Post 4 by @fria — 2024-11-26T17:49:22Z

Yes

---

## Post 5 by @phnx — 2024-11-26T17:55:35Z

You’re also trusting Apple with the OS as a whole so I’m not convinced impersonating developer certs should be your largest concern if you don’t trust Apple whatsoever.

---

## Post 6 by @anon94009837 — 2024-11-26T17:56:40Z

my thoughts too.

---

## Post 7 by @jonah — 2024-11-26T18:01:04Z

Well, Apple doesn’t verify every app signature, so there could be a time period between an Apple developer certificate being compromised and Apple revoking it.

I’m not sure what the likelihood that a developer leaks their Apple certificate but not their GPG key is though, probably pretty small… depends on their build workflow I suppose.
