• Zwuzelmaus@feddit.org
    link
    fedilink
    English
    arrow-up
    57
    arrow-down
    2
    ·
    4 days ago

    Google’s updated Play Integrity API

    How can these people talk about “integrity” when they break real existing phones?

    I call this the opposite of integrity.

    • tinned_tomatoes@feddit.uk
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      46
      ·
      edit-2
      4 days ago

      Bit hyperbolic, don’t you think? Rooted/Custom ROM users are so tiny, and they typically use security vulnerabilities to obtain root access. It’s not exactly surprising that Google closes those vulnerabilities when it can.

      Google can’t exactly make root access and custom ROMs easier to use in 2025. It isn’t 2010 anymore - as soon as rooting becomes easy again, and people are bypassing security measures you know the big orgs, copyright holders and children’s apps will complain to the media and suddenly Google has a shitstorm to deal with.

      Just wait until they find another vulnerability, lol.

      • Zak@lemmy.world
        link
        fedilink
        English
        arrow-up
        46
        ·
        4 days ago

        Many devices, including Google’s own Pixel devices have user-unlockable bootloaders. No security vulnerabilities are involved in the process of gaining root access or installing a third-party Android distribution on those devices.

        What’s going on here isn’t patching a vulnerability, but tightening remote attestation, a means by which a device can prove to a third party app that it is not modified. They’re selling it as “integrity” or proof that a device is “genuine”, but I see it as an invasion of user privacy.

        Google can’t exactly make root access and custom ROMs easier to use in 2025.

        Sure they can. They’re in a much stronger position to dictate terms to app developers than they were in 2010 when it was not yet clear there would be an Android/iOS duopoly.

        They don’t want to though, because their remote attestation scheme means they can force OEMs to only bundle Google-approved Android builds that steer people to use Google services that make money for Google, and charge those OEMs licensing fees. A phone that doesn’t pass attestation isn’t commercially viable because enough important apps (often banking apps) use it.

      • 0x0@infosec.pub
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        4 days ago

        The fuck did you just call me? Ill have you know im actually HUGE