4 ms·
In fact, it requires attestation: even if you install Google Play on some Android in an emulator/container/VM, on an alternative Android distro or in a rooted d
by roundabout-host 3mo ago
In fact, it requires attestation: even if you install Google Play on some Android in an emulator/container/VM, on an alternative Android distro or in a rooted device, the app will not accept it.
- literalAardvark 3mo agoWth. Does it at least have the decency to use aosp attestation? Or are they just happy to give the keys to the kingdom to Google and require Play Protect?
- izacus 3mo agoHow would you "use AOSP attestation"? The point is that the signatures are compared against a database of certified builds - and that exists on Google servers. If you want AOSP attestation, you need to build your own database to compare against.
- roundabout-host 3mo agoEven if they did that, it would not be OK. Free software is no longer free if it has to be on a list.
- literalAardvark 3mo agohttps://grapheneos.org/articles/attestation-compatibility-guide https://grapheneos.org/articles/attestation-compatibility-gu... It exists on Google's servers for lock in reasons alone.
- izacus 3mo agoGrapheneOS guy went on a very extensive rant on Mastodon when someone wanted to create an independent, European, list that could be used by apps to verify attestation. They want apps to hardcode theirs specifically. Which makes sense for them - after all, that makes their competitors break and their ROM doens't.
- roundabout-host 3mo agoEven with the "independent European" list, you would still be unable to use a custom OS not in it.