104 ms·
This entire issue is a disaster of a Github issue. It looks like its on the entirely wrong repository. I did eventually find the text in another repository; the
by Deukhoofd 3mo ago
This entire issue is a disaster of a Github issue. It looks like its on the entirely wrong repository. I did eventually find the text in another repository; the one for the Android reference implementation: https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui/commit/6b126d98606ed42d1fc845ece8f8a768cc50de6e https://github.com/eu-digital-identity-wallet/av-app-android...
It was removed from there to clarify the entire "Hey, this application is not done yet"
It being in the reference implementation instead of the spec is a massive difference. One means that it's just there to show an example, and we should push national governments to do it better in their implementations, while the other would mean that it'd be a requirement for all implementations, which it doesn't appear to be.
It also looks like the reference implementation removed that functionality entirely several months ago: https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui/commit/20c8be04bfccf231bf93f600d1e9172fc03d3f4e https://github.com/eu-digital-identity-wallet/av-app-android...
- 3abiton 3mo agoHonestly, root detection is a cat and mouse game. So many ways to spoof it. Same with Play Integrity. If the goal is to prevent bad actors, it will never work really. It will be just a big headache for the citizens. Look at how gatekeeping certain websites is working. VPNs became mainstream. So are proxies too especially for bad actors. Malicious actors have just to pay up a service to do so. And I am sure it will be the same with Android (it already is with keyboxes you can purchase to spoof play integrity)
- a2128 3mo agoIn my opinion the whole "it's just a reference and national govs can decide" is a nonsense excuse to diffuse blame in a circle. The only outcome is that national governments will closely follow the reference and reuse the decision, the citizens of each country then have to manually complain to their own government individually, at which point they might get ignored because, well the reference implementation has it or talks about it, so they're just following the recommended security requirements, and who are you anyway to be demanding our system get less secure are you some kind of cybercriminal? Play Integrity is still recommended to be evaluated in the documentation, with no mentions of its consequences. https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui/blob/main/docs/production-hardening-guide-v3.8.md https://github.com/eu-digital-identity-wallet/av-app-android...