• GrapheneOS@grapheneos.social
    link
    fedilink
    arrow-up
    1
    ·
    1 month ago

    @sposadelvento @_Riccardo_ @tecnologia Apps using the hardware attestation API can choose to trust more attestation roots than the Google ones and can also choose to support alternate operating systems via their verified boot key fingerprints. We document how to use it to support GrapheneOS when verifying device/OS/app integrity. This is more secure than the approach of using the Play Integrity API and there are no downsides for apps. The hard part is convincing them to do any extra work at all.

    • GrapheneOS@grapheneos.social
      link
      fedilink
      arrow-up
      1
      ·
      1 month ago

      @sposadelvento @_Riccardo_ @tecnologia It’s a problem because apps adopting this are mainly doing things how Google documents it without even considering the existence of GrapheneOS. For their digital ID and age verification standards, the EU should be defining actual security requirements based on their needs and then only enforcing those with it open to any devices or operating systems. They really shouldn’t give any special advantage to ones licensing Google Mobile Services.