3 ms·
One extremely disappointing thing that Android has been getting under the hood with Google images is ... Play integrity. This used to be a relatively simplistic
by fcpk 1y ago
One extremely disappointing thing that Android has been getting under the hood with Google images is ... Play integrity.
This used to be a relatively simplistic system with three tiers:
0 - you are not certified for anything
1 - basic integrity, you need to have a genuine android device running google play services
2 - device integrity, you need to have a genuine android device with core requirements on play and no rooting
3 - strong integrity, you need a locked bootloader and signed image with recent security update
This API/requirements set was uniquely put by pressure from various vendors(think banks and various "security-certification" obsessed parties), and was already quite unpleasant, as it excludes any form of rooting, even if your root-access is adb only. But it gets worse as now non-official images are getting excluded not only from strong integrity[0] but also device integrity. Numerous apps are now requiring device integrity and hence won't be usable even on a locked, signed android image if it's not google or vendor-official.
It actually gets worse. Google has been silently restricting the api results(as of may):
- basic requires a certified device with an android platform key attestation
- device now requires a hardware verified boot, with locked bootloader and recent security patch. This excludes lots of devices
- strong requires security patch on all partitions
And it gets even worse. On recent play stores & android versions, as apps have to be installed or updated by google play to get a full integirty response. no more sideloading APKs or alternative stores.
This is nothing but a clear move to a full lock-in to play store, where the majority of vendors live, to end up with a fully locked a-la-apple ecosystem. This doesn't improve security, people that know still have ways to bypass those restrictions when needed. All it does is give the illusion of safety.
I would personally feel like:
1 - rooting should be allowed on a certified device with most apps still working. This could be done with a locked bootloader too if they provided such an image for debug.
2 - alternative os, like graphene, should be given a way to pass all attestations, as well as alternative stores, provided they follow a set of constraints.
With this in mind, I can't be positive about android 16 and new versions going down a grim locked future.
[0] https://discuss.grapheneos.org/d/6361-play-integrity-api-and-future-of-grapheneos https://discuss.grapheneos.org/d/6361-play-integrity-api-and...
- charcircuit 1y ago>rooting should be allowed on a certified device I don't think this should be allowed because rooting breaks the Android security model. Devices that don't follow at least Android's security model should not be allowed that way apps understand the security model of Android. >grapheneos should be given a way to pass all attestations There already is the Android attestation API that can be used to attest grapheneos. But I do think it would be nice if Play Integrity would expand beyond just Play Protect Certified devices, to devices which can prove they offer a similar or greater level of security.
- fcpk 1y agoI think it's a bit disingenuous to mix together the security model and the ability to do things on a device you own. Should the default android be locked, with no root, play store verifying apps, etc, absolutely. This is great for the average user that desires nothing more than just running play store apps. Should you have the ability to run what you want on your phone, and copy the data from the app that you installed, after accepting the risks? absolutely. It is already non trivial to install root, and adb locked root for example makes things vastly more secure even in that case(that is, you can only adb su into your phone, you can't grant the permission to an app directly). Especially with locked adb having fingerprint verification. On grapheneos you can get basic. You can't get device, which is now needed by a lot of applications. See another example at: https://discuss.grapheneos.org/d/18118-play-integrity-meets-device-integrity https://discuss.grapheneos.org/d/18118-play-integrity-meets-... Play integrity by locking everything to the Google/Main vendors is making it less and less possible to run non-primary images/oses. And it's not for users security, it's for apps security, so this is purely to reassure the industry, and yet it is just another security theater. Running with strong integrity on a rooted device is possible with semi-significant effort, and that's good. It means that we're not relying on security by obscurity, and we can look at what's running on the phones.
- charcircuit 1y ago>Should you have the ability to run what you want on your phone Sure, but that doesn't require root to do. The OS can expose capabilities that apps want instead of requiring security to be entirely bypassed with root. >and copy the data from the app that you installed, after accepting the risks? No, because that violates Android's security model. If an app wants to have a authentication token live on a single device then being able to copy it violates that and can result in multiple different devices sharing the same token. >Google/Main vendors is making it less and less possible It's app developers doing this.
- spaqin 1y ago> rooting should be allowed on a certified device i don't think this is enough - rooting should be allowed on any device that you own, rather than the device owning you.
- fcpk 1y agoI do agree, but I understand that we live in an imperfect world with people needing some level of reassurance even if it's pointless...
- privacyking 1y agoAgree on all counts. I'm going to trial/move to iOS because of this. If I'm going to live in a walled garden, might as well live in the better one. Hopefully I can live with the shittier notifications/keyboard/lack of back button; I think the rest of iOS is overall better than a degoogled android experience. I also don't really understand the point of all these strong integrity checks being enforced e.g. with banking apps or the alike. You can already just go to the corresponding website (and do the same actions) on a compromised device, how does restricting the app version provide any benefit?