If signature spoofing is confined to apps that I designate as spoofed (such as microg), then I'm okay with it. No security problem as far as I'm concerned.
I'd like to see people make their own apps that don't rely on Google services (or faked Google services) of course, like the Linux ecosystem.
I'd like to see people make their own apps that don't rely on Google services (or faked Google services) of course, like the Linux ecosystem.