4 ms·
>With hardware remote attestation there will no longer be any point in even owning an android phone anyway. Android is obviously inferior to iOS in every way bu
by thedriver 4y ago
>With hardware remote attestation there will no longer be any point in even owning an android phone anyway. Android is obviously inferior to iOS in every way but the whole point was you could have control over the machine and do whatever you wanted. Now apps will be able to verify that you "tampered" with the phone and will refuse to run, and since it's hardware cryptography it cannot be faked without massive effort. Might as well get an iPhone which at least isn't a shitty Google product.
Wait a minute, will something like this really come to Android phones? I guess that installing a custom rom will become impossible at the same time?
If this happens, then there truly isn't going to be much point in using an Android phone over an iPhone
- boring_twenties 4y agoIt won't become impossible to install a custom rom, it will simply become impossible to use many if not most popular apps. Android already provides a mechanism for apps to refuse to run on modified devices, it's called SafetyNet and is widely used for example by banking apps. Currently, it's usually possible to trick it, but with hardware attestation it will become practically impossible.
- jqpabc123 4y agoYes, some banking apps do this. The simple solution --- install the bank's web site as an app. Go to the site, click the browser menu button (3 dots on Android or up arrow on iOS) and select "Add to Home Screen". You now have a link icon on your phone that looks and acts just like any other app. Some banks (Chase for example) offer a "Progress Web App" which removes the browser interface elements so the causal observer can't even tell it's not a native app. https://www.howtogeek.com/342121/what-are-progressive-web-apps/ https://www.howtogeek.com/342121/what-are-progressive-web-ap...
- boring_twenties 4y agoI am able to use Chase's app on my LineageOS + Magisk rooted device. The annoying part is that they seem to disable fingerprint login, so now I have to copy/paste the password every time.
- cuteboy19 4y agoSurely bitwarden can help
- jqpabc123 4y agoWait a minute, will something like this really come to Android phones? Google has been doing this for quite some time to prevent unlocked devices from accessing the Play Store. The solution is to avoid Google Play --- along with all other Googly things.
- charcircuit 4y agoThis is a security feature and the play store doesn't require it AFAIK. Apps can choose to use it as a signal on whether a client is secure. Unlocked devices are insecure because an attacker can flash a malicious image and steal all of your sensitive data such as an authentication token for your bank account. If your solution is to just be less secure go ahead, but don't complain when services don't want to serve you or treat you different since you are less secure than the other users.
- matheusmoreira 4y agoYeah, sure. An "optional security feature". > don't complain when services don't want to serve you or treat you different since you are less secure than the other users Hell no. They should not be allowed to discriminate against me just because I chose to own my system. They should not even be able to figure out what software I'm running, to say nothing of "treating me different". "Don't want to serve us" unless we let them invade and own our machines? Please. This should be illegal.
- charcircuit 4y ago>They should not be allowed to discriminate against me just because I chose to own my system. App developers don't care if you own your system. They just want a way to prove that the device their app is running on is secure and that the client has not been modified. If there was a way for you to prove that to them they wouldn't mind. >They should not even be able to figure out what software I'm running, to say nothing of "treating me different". They just want to know that the client has not been tampered with so that they know you are not going to shall user's tokens, scrape people's information, or mondo automated actions as a bot. A signal that you are using the vanilla client makes you much more trust worthy to a service. >"Don't want to serve us" unless we let them invade and own our machines? Apps aren't invading your machine. They just want some guarantees about the environment they are operating in. The information that they get from you is the package's name, certificate, version, whether it's from the play store, whether your device passes integrity checks, and whether the app is properly licensed.
- matheusmoreira 4y agoGoogle SafetyNet can be used to attest that the device has not been modified or "tampered" with. Basically Google cryptographically proves it owns your phone and has control over what you do with it. You can fake the software attestation right now with stuff like Magisk but once it moves to hardware attestation it's over. You'll be able to install custom systems but what's the point if they can't run the apps you want or need? Why wouldn't an app require this? Banks want it because "fraud", streaming services want it because "piracy"... You can come up with pretty much any reason for any "rightsholders" to want control over our computers. If WhatsApp starts requiring this, it's either accept Google control or my phone turns into a paperweight.