6 ms·
[flagged]
by linwangg 2y ago
[flagged]
- protimewaster 2y agoMeanwhile, apps are starting to block GrapheneOS (and others), because GrapheneOS doesn't pass the Play Integrity "security" test. At the same time, stock devices that haven't received security updates for 5 years (and are vulnerable to known exploits) do pass Play Integrity. Google is basically using Play Integrity to limit the functionality of Android variants like GrapheneOS (while pretending it's about security), and app developers are, for some reason, happily going along with it.
- Retr0id 2y agoPlay Integrity is DRM masquerading as a security feature. Unfortunately, many app developers care more about the former.
- protimewaster 2y agoI kinda understand it if a developer actually wants DRM. But why does my bank care to use it? I'm not likely to pirate my banking app.
- notpushkin 2y agoBecause it says “security” and looks good on paper. For some inexplicable reason, many banks don’t seem to care about actual security, even the modern ones. (Shame on you, Revolut)
- brookst 2y agoYour bank loses money when keyloggers/etc are used. Play integrity claims to avoid this problem, and a rooted device with an alternative ROM is a big red flag. There are nuances here and there are probably ways app developers could support legit Graphene but not a malicious fork, but that’s a lot of work and expertise to reach an extra 0.01% of the population.
- protimewaster 2y agoI understand the idea, but GrapheneOS doesn't even provide any kind of official support for rooting. It's not that they're checking to see if the device is rooted, they're just checking to see if it has Google's checkmark. Meanwhile, rooted devices can pass Play Integrity (since they can spoof all the necessary bits via root).
- brookst 2y agoIsn’t play integrity based on PKI and hardware root of trust? How does a rooted device fake the signed ROM / bootloader / etc?
- protimewaster 2y agoI haven't read about it too much since I'm not rooted, but lots of users report being able to use apps that require integrity with various root approaches (e.g., https://www.reddit.com/r/Magisk/comments/19c1dv0/help_can_i_pass_the_playintegrity_strong/ https://www.reddit.com/r/Magisk/comments/19c1dv0/help_can_i_...)
- yjftsjthsd-h 2y ago> Your bank loses money when keyloggers/etc are used. Play integrity claims to avoid this problem, and a rooted device with an alternative ROM is a big red flag. Well... no? Maybe a device with things running as root is a yellow flag, but malware isn't going to replace the ROM or install a normal user-controlled root solution. Or put differently, if your "security" system flags the latest version of Lineage OS but doesn't flag a year-old stock ROM with known CVEs, then your system is actively fighting against security.
- Retr0id 2y agoYou're not likely to pirate your own banking app, but thieves would love to patch the APK (or OS itself) so that it works "normally" except for skimming off credentials etc. in the background. This is functionally equivalent to what happens in app piracy (or game cheating, etc.), and all the same mechanisms are used to try to prevent it. I don't blame the banking apps, it makes sense given their incentives and constraints. But if Play Integrity existed to serve the user, it would answer only to the user, and not "snitch" the device integrity status to apps and their backends.
- Hizonner 2y agoApp developers are going along with it because many of the third-party ROMs so insolently take the view that a user's device should serve the user.
- brookst 2y agoAnd some of those users are malicious. It’s easier to cut off small populations than to sort out the good ROMs from the evil ones.
- Hizonner 2y agoIf your app can be manipulated to your disadvantage by the user, then you are putting undue trust in client-side software, and you need to rearchitect your service. Or, sure, you can stick with your lazy, slipshod design and try to paper it over with (unreliable and stupid) attempts to disempower the user.
- brookst 2y agoSecurity isn’t binary, it’s about layers and probabilities. A client that attests play integrity is less likely to be an attacker than one that isn’t. That doesn’t mean it’s impossible to use an attested device in an attack, or that all non-attested devices are malicious. A good heuristic is that if you find yourself using absolutes and dramatic, insulting language… you do not have a valuable insight about security.
- Hizonner 2y ago> Security isn’t binary, it’s about layers and probabilities. A truth frequently abused to excuse obviously bad practices. > A client that attests play integrity is less likely to be an attacker than one that isn’t. A comfortable, yet completely unjustified, assumption.
- protimewaster 2y ago> A comfortable, yet completely unjustified, assumption. I agree. Knowledgeable users are passing Play Integrity on rooted devices. The idea that these knowledgeable users who are willing to bypass local security checks are more trustworthy than users who honestly fail the security test feels like a strange stance on security. If you want assurance that your code won't run on modified devices, don't let users run the code at all. Have them come into the bank branch and use hardware that you control.
- everdrive 2y agoThis is very well said. Every time the subject of smartphones comes up, people will claim there are workarounds to the privacy, security, repair-ability, or usability issues. These arguments have some merit, but these workarounds are almost always very fragile, tenuous, and completely out of reach for most normal users. If you come to rely on these workarounds, you'll be playing a game of cat and mouse for years as Google and Apple find different ways to indirectly ruin your workflow.
- jeroenhd 2y agoSecurity, from an app developer perspective, isn't necessarily about the user getting exploited. It's also about protecting the app's interests. Phones rooted by malware will fail Play Integrity, if checked well (hardware verification). For apps that are on the hook for paying for users' mistakes (banking apps, for instance), that makes a lot of sense. Games care more about preventing cheaters than about users getting their Bluetooth stack getting exploited. Remote attestation like Play Integrity can be used for legitimate security purposes, like in managed MDM settings, but it's not just about security.
- iszomer 2y agoIs everyone forgetting that GrapheneOS only runs on one specific brand, namely Google's Pixel line exclusively? - https://grapheneos.org/faq#supported-devices https://grapheneos.org/faq#supported-devices