• kbal@fedia.io
    link
    fedilink
    arrow-up
    55
    ·
    1 year ago

    The key difference between “Android’s Play Integrity API” and this new thing which they are no longer proposing to put in Chrome but into Android WebView instead is the remote part of “remote attestation”.

    The article does not make it entirely clear, but the new thing looks to be exactly the same as the old Web Environment Integrity we knew and hated, but with a new name and temporarily exclusive to Android.

    • BearOfaTime@lemm.ee
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      1
      ·
      1 year ago

      I’m so glad there are devs behind things like Lineage, DivestOS and Graphene. I’m currently setting up a oh one using Divest without Google.

      I’ll be buying some Pixel 5’s to get me through the next 5 years (my current phones are from 2018, and really fast with Lineage or Divest, and load a bunch of apps, and automation).

  • Keith@lemm.ee
    link
    fedilink
    English
    arrow-up
    50
    arrow-down
    1
    ·
    1 year ago

    As someone who uses root (not at the moment but plans to) as I believe in owning my devices, fully, this is horrible. We still need to oppose this.

    • LiveLM@lemmy.zip
      link
      fedilink
      English
      arrow-up
      34
      ·
      edit-2
      1 year ago

      I know right? The article touches on this:

      Google said the inspiration for the original Web Integrity project was Android’s Play Integrity API, which already scans your phone for root privileges and denies access to things

      ^^^ this should have never, ever been a thing!

      • 0xD@infosec.pub
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        5
        ·
        1 year ago

        That is just standard and a completely sensible security measure for preventing people from tampering with an application. It cannot replace proper, server-side security measures but is a big step. Especially for stuff like banking applications.

        • BaldDude@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          7
          ·
          edit-2
          1 year ago

          I never really understood that:

          If I’m using my browser to do banking via the website, Having root privileges and tampering with the Browser running the applications is not an issue.

          If i use the banking app, Having root privileges suddenly become a problem.

          –> To me, it doesn’t look like the problem is technical, but that users are accepting things on mobile that they wouldn’t accept on a PC.

  • RooPappy@kbin.social
    link
    fedilink
    arrow-up
    28
    ·
    edit-2
    1 year ago

    Big fucking sigh. I’ve been an Android user since the T-mobile G1, and I have ferociously defended the platform against iPhone for that entire time.

    Is there a 3rd option? Or do I have to learn to love the enemy? I won’t be a part of the problem with privacy just because I’m too lazy to change.

    • BearOfaTime@lemm.ee
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      1
      ·
      1 year ago

      Use Graphene, Lineage or DivestOS (fork of Lineage) . Graphene and Divest enable you to sandbox all Google BS if you need it, and Dos uses their own we view from Mull.

      • RooPappy@kbin.social
        link
        fedilink
        arrow-up
        4
        ·
        1 year ago

        I love the idea, and would be willing to be an early adopter of a linux phone… but its tough to give up application support.

    • BaldDude@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      5
      ·
      edit-2
      1 year ago

      Honourable mention for Sailfish OS

      https://en.wikipedia.org/wiki/Sailfish_OS

      The commercial version comes with an android emulator.

      It’s not recommended for non-technical people, it sometimes crashes, it has random bugs that will drive you insane, and currently the weather app can’t connect to the service that provides the weather data.

      But:

      The people making it are not seeing you as the product and you will be free of all the bullshit.

      … and i love it :)

    • shapis@lemmy.ml
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      3
      ·
      1 year ago

      I have ferociously defended the platform against iPhone

      Why tho

      • RooPappy@kbin.social
        link
        fedilink
        arrow-up
        12
        ·
        edit-2
        1 year ago

        Because Apple are: closed system, unrepairable, proprietary, refuse to adopt standards, elitist and exclusionary, and generally less flexible and customizable. They are a baby toy, they are any recent BMW, and they are jerks about it.

        And somehow, that’s becoming the better option over thieves and scammers with bad intentions. I may have to go with the assholes over the bastards. It doesn’t feel great.

        • jol@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          3
          ·
          1 year ago

          I get you, but calling iOS a toy just makes you sound childish and ignorant. I don’t use apple for the same reasons, but iOS right now offers by far the most polish, mature and thought-through experience. In the meantime, Android continues to change everything on a whim every couple versions to nonsensical defaults. The UI keeps getting worse.

          But I just can’t stand the inability of customizing iOS. Google is strangling the platform, replacing FOSS features with Google counterparts, and if it wasn’t for Samsung and maybe a few other big ones, they would probably have abandoned AOSP by now.