121 points

The site provides a nice TL,DR:

  • Efforts like Graphene OS face increasing pressure from apps that refuse to run on non-standard Android.
  • The custom ROM project characterizes Google’s approach to device attestation as incomplete and flawed.
  • Graphene OS is prepared to take legal action if Google won’t let it pass Play Integrity checks.
permalink
report
reply
8 points

Thanks

permalink
report
parent
reply
5 points

The whole idea of device attestation is flawed. Majority of apps shouldn’t be dealing with it at all, but minding their own business.

permalink
report
parent
reply
2 points

The hero we don’t deserve

permalink
report
parent
reply
62 points
*

On a personal note, I’m annoyed that our national ID app doesn’t work with graphene OS.

There are workarounds by patching out the security check from the app and sideloading the newly created app, but that is just annoying and has to be repeated for every update.

I just don’t see how rigorose device checks that lock out graphene users, but allow any Android 8.0+ device (where security support ended more than 3 years ago) make ANY sense.

Edit: I tried it again today, it now lets me skip with a warning about the bootloader.

permalink
report
reply
32 points

It isn’t a security feature, more like a backdoor checkbox.

permalink
report
parent
reply
23 points

Or frontdoor checkbox for that matter, given that it’s the literal device owner that takes the action tripping their “security” tripwire.

permalink
report
parent
reply
15 points
*
Deleted by creator
permalink
report
parent
reply
1 point

What national ID is it? I hope it isn’t the Belgian ItsMe app because I want to try putting lineage on my xperia 5 ii since it has a flaky fingerprint scanner now (software problem it seems)

permalink
report
parent
reply
2 points

ID Austria

permalink
report
parent
reply
0 points

“National ID app” sounds like something from 1984. I personally would never agree to something like that.

permalink
report
parent
reply
9 points

I understand that even the concept is scary to some, especially to our friends on the other side of the atlantic.

However, it isn’t really anything else than a 2FA app, similar to most banking apps. When you interact with a government service (like taxes, social security), you have to approve the login on your phone.

permalink
report
parent
reply
-4 points

Is it libre? Can I opt out and use physical ID? If the answer is no to any of those you shouldn’t use it.

permalink
report
parent
reply
52 points

It’s high time Custom ROMs and users alike did this. I cannot run a custom ROM on my primary device due to play integrity shenanigans some apps may have.

permalink
report
reply

Looking forward to this. I don’t run a custom ROM myself but I am rooted, primarily to revoke permissions from Google apps and to back up my OS and app data as I desire.

However I’d much prefer to be able to run something like GrapheneOS on a Pixel if it meant I could run apps that are picky about Safetynet/Play Integrity, such as banking apps and the like

permalink
report
reply
7 points

CalyxOS lets me run most safety net stuff, though notably Pokemon go stopped working all of a sudden.

permalink
report
parent
reply
8 points

CalyxOS lets me run most safety net stuff…

SafetyNet is deprecated.

https://developer.android.com/privacy-and-security/safetynet/deprecation-timeline

permalink
report
parent
reply
4 points
*

Most things works fine, if they don’t there are ways around it, like installing the neutered play version. Only hard NO currently is Gpay.

Not missing root functionality things at all

permalink
report
parent
reply
19 points

Not gonna like. This is interesting. Who knew that messing with the ROM community could put Google in trouble.

permalink
report
reply
2 points

“Trouble”

I think they will be fine as they have a huge market share in Android

permalink
report
parent
reply
2 points

I think you’d be surprised. CalyxOS are making massive claims. If the US or the EU investigate, Google could be fined or worse.

permalink
report
parent
reply
2 points

Seems at least plausible, given the whole “gatekeeper” regulations (EU).

permalink
report
parent
reply

Android

!android@lemdro.id

Create post

The new home of /r/Android on Lemmy and the Fediverse!

Android news, reviews, tips, and discussions about rooting, tutorials, and apps.

🔗Universal Link: !android@lemdro.id


💡Content Philosophy:

Content which benefits the community (news, rumours, and discussions) is generally allowed and is valued over content which benefits only the individual (technical questions, help buying/selling, rants, self-promotion, etc.) which will be removed if it’s in violation of the rules.


Support, technical, or app related questions belong in: !askandroid@lemdro.id

For fresh communities, lemmy apps, and instance updates: !lemdroid@lemdro.id

💬Matrix Chat

💬Telegram channels / chats

📰Our communities below


Rules

  1. Stay on topic: All posts should be related to the Android OS or ecosystem.

  2. No support questions, recommendation requests, rants, or bug reports: Posts must benefit the community rather than the individual. Please post to !askandroid@lemdro.id.

  3. Describe images/videos, no memes: Please include a text description when sharing images or videos. Post memes to !androidmemes@lemdro.id.

  4. No self-promotion spam: Active community members can post their apps if they answer any questions in the comments. Please do not post links to your own website, YouTube, blog content, or communities.

  5. No reposts or rehosted content: Share only the original source of an article, unless it’s not available in English or requires logging in (like Twitter). Avoid reposting the same topic from other sources.

  6. No editorializing titles: You can add the author or website’s name if helpful, but keep article titles unchanged.

  7. No piracy or unverified APKs: Do not share links or direct people to pirated content or unverified APKs, which may contain malicious code.

  8. No unauthorized polls, bots, or giveaways: Do not create polls, use bots, or organize giveaways without first contacting mods for approval.

  9. No offensive or low-effort content: Don’t post offensive or unhelpful content. Keep it civil and friendly!

  10. No affiliate links: Posting affiliate links is not allowed.

Quick Links

Our Communities
Lemmy App List
Chat and More

Community stats

  • 2.7K

    Monthly active users

  • 2.7K

    Posts

  • 34K

    Comments