Google Play’s latest security change may break many Android apps for some power users. The Play Integrity API uses hardware-backed signals that are trickier for rooted devices and custom ROMs to pass.
-
This post did not contain any content.
If I don't have Play Integrity spoofed, my iPhone friends get an error when they try to RCS message me. This pretty much breaks communication for me.
-
At this point I'm leaving a paper trail in my comments. Sigh, I'll keep it short and sweet.
If you're using ReVanced to hack and get through Duolingo, then I think you should just drop the service. There are countless free resources out there that do a better job, and aren't predatory or make you hate learning. Duolingo is good for beginners and about a month or two of learning. Please let that app go, especially since the CEO thinks AI is a suitable replacement for the education system...
At some point I will but I'm not currently ready to make that transition. My friend and I are using Duolingo together and the social aspect plus the familiarity of the structure have been really helpful
They walked back the ai thing (at least that's my understanding about it, I think there was a statement about it, not that that means much) but it's very clear it wont be something that's likely to work for me long term
But for the time being the structure that it provides and its format has helped me build a routine and actually stay pretty consistent, and I don't think I'm at a place yet where I can transition away from it
But I have checked out the Foss options and there were some neat supplemental tools on f-droid, and at some point I'll go through the play store and try out direct alternatives
-
This trend of being actively hostile toward your user base is so confusing to me.
It’s so confusing it only makes sense to business majors. /s
-
Nothing anti-trust about genuine un-rooted and un-modified devices having secure access to the play store.
It's when you lock out phones that come from Huawei/Oppo etc. because they are Chinese, that you might be able to make a point.It is when the play store is not the only store allowed on devices. Their play services, with this change, are again acting as a monopoly, and again will be again be sued by the eu for violating anti trust laws.
-
If I don't have Play Integrity spoofed, my iPhone friends get an error when they try to RCS message me. This pretty much breaks communication for me.
This is the future of the Big Tech Internet if we're not careful. Attestation to be able to use communications and other websites.
-
Seriously, what is wrong with Google?
Google is doing this because they have incentives to do so. They want to block malicious actors like attack their platforms.
Other companies want to lock down their own apps because they don't think users should be permitted to do anything other than use their apps exactly as they want.
I don't like it as a user, but I also see the reason why companies want this by being on the security side of software.
-
Deleted
If you don't need any Google malware, you aren't at risk.
GrapheneOS comes without them by default.
-
I've always been of the opinion that apps are almost always useless because there is usually a way to do it through a web browser and if there isn't I don't need it. And its usually better because then I have more control (in firefox anyway).
For example the youtube app is entirely unuseable but if I open firefox and use ublock and no script then suddenly I can actually use the website.
i use firefox forks for mobile, op12r-
-
Deleted
What do people even do in there ?
In France some banks illegally force users to use the banking application to approve online transactions as a security feature.
They could implement OTP as an alternative but they don't because they are lazy.
-
This post did not contain any content.
Time to get downvoted to oblivion.
I see a lot of people questioning why Google would do this and the answer is pretty simple.
Google created a tool a long, long time ago which was meant to make sure traffic from a device was "legit". This tool is 100% optional and app developers can use it if they would like. However, the tool was easy to bypass, so over the years Google has been making the tool harder and harder to bypass.
This article is just sharing news that Google is once again making this tool harder to bypass.
So why is Google doing this? They are doing this because they don't want their tool to be bypassable. Their tool is worthless if it can be bypassed.
The tool in question here is the Play Integrity API (previously known as the SafetyNet Attestation API). This is a tool that is offered to app developers that app developers can take advantage of if they want. The selling point of the tool is if you have operation in your app that is critical, you can try to prevent some abuse by verifying that the app is running on a "trusted build of Android" and that the app itself has not been modified from the original. That's all the tool does.
This isn't a new API. This isn't something Google is trying to force app developers to use. No. From Google's point of view, they are just making sure their tool does it's job properly.
As for why companies might choose to use this tool, a big reason is because Android is a huge target for fraud. Apple has locked all their stuff down so it is much harder to commit fraud on iOS (not impossible though). Although Apple offers something similar, there is generally less fraud coming from iOS devices vs Android. It's the double-edged sword of having a more open platform.
Companies are obviously not going to be happy to be the target of fraud so they have to weigh their options. Either they block a small percentage of their users that are possibly legit by implementing Play Integrity API or they risk losing a % of their income to fraud.
Now you can disagree with the tool's job, I'm not trying to argue whether the tool is good or bad. That is extremely subjective, but hopefully this answers why Google is making this change.
-
This post did not contain any content.
Wasn't this on Pixels already?
-
It doesn't make it "tricky", it makes it impossible.
Troja has been impossible to conquer. Until.
-
This post did not contain any content.
The reason I felt forced to iOS. No more choice. No more GrapheneOS or CalyxOS for me.
Or at least that would make my life very difficult. National ID authentication, banking apps had stopped working.GG Google. Destroy what made Android.
-
Time to get downvoted to oblivion.
I see a lot of people questioning why Google would do this and the answer is pretty simple.
Google created a tool a long, long time ago which was meant to make sure traffic from a device was "legit". This tool is 100% optional and app developers can use it if they would like. However, the tool was easy to bypass, so over the years Google has been making the tool harder and harder to bypass.
This article is just sharing news that Google is once again making this tool harder to bypass.
So why is Google doing this? They are doing this because they don't want their tool to be bypassable. Their tool is worthless if it can be bypassed.
The tool in question here is the Play Integrity API (previously known as the SafetyNet Attestation API). This is a tool that is offered to app developers that app developers can take advantage of if they want. The selling point of the tool is if you have operation in your app that is critical, you can try to prevent some abuse by verifying that the app is running on a "trusted build of Android" and that the app itself has not been modified from the original. That's all the tool does.
This isn't a new API. This isn't something Google is trying to force app developers to use. No. From Google's point of view, they are just making sure their tool does it's job properly.
As for why companies might choose to use this tool, a big reason is because Android is a huge target for fraud. Apple has locked all their stuff down so it is much harder to commit fraud on iOS (not impossible though). Although Apple offers something similar, there is generally less fraud coming from iOS devices vs Android. It's the double-edged sword of having a more open platform.
Companies are obviously not going to be happy to be the target of fraud so they have to weigh their options. Either they block a small percentage of their users that are possibly legit by implementing Play Integrity API or they risk losing a % of their income to fraud.
Now you can disagree with the tool's job, I'm not trying to argue whether the tool is good or bad. That is extremely subjective, but hopefully this answers why Google is making this change.
Yeah except that bot farms already use hardware that will pass the checks, unlike regular harmless users who will get hurt by this. Google comes after the good guys
-
This post did not contain any content.
RIP banking apps and Mc Donalds on GrapheneOS
-
So instead of completely using FOSS softwareonly, you just give in to the corps?
This has nothing to do with FOSS, of which plenty exists on iOS
-
This has nothing to do with FOSS, of which plenty exists on iOS
I have yet to see a FOSS ROM for IOS devices. Or like any FOSS app I use, like Etar, a free version of Sncthing, a Retroarch with at least the same functionality as on android, a browser that dosent use WebKit, and a terminal emulator or at least a free fully featured vim app that can access my full storage.
Also, they can't break Costum ROMs, since AOSP is Open Source.
Also, since none of my devices can run AltStore in order to validate side loaded stuff every 14 days, I have to get everything from the App Store, since AltStore is kinda dead
And also I want to develope my own apps, but I neither have an Apple Desktop, noir do I have 99€ a year to pay for Apples Private key.
TL;DR: Even with Gservices, Android is still just better then iOS since you can just Root it and disable tracking stuff (or not root it and just disable the tracking apps but not Gservices)
-
What do people even do in there ?
In France some banks illegally force users to use the banking application to approve online transactions as a security feature.
They could implement OTP as an alternative but they don't because they are lazy.
Which ones? I've been on Boursorama, CA and SG, and they all provide SMS 2FA if you don't want to use the app.
-
Which ones? I've been on Boursorama, CA and SG, and they all provide SMS 2FA if you don't want to use the app.
It depends which local branch. CA and the Caisse d'Epargne lied to me about it. BoursoBank is good though.
-
If I don't have Play Integrity spoofed, my iPhone friends get an error when they try to RCS message me. This pretty much breaks communication for me.
I have zero problems with this on Lineage. ?? No spoofing either, just Lineage.
-
-
The State of Consumer AI: AI’s Consumer Tipping Point Has Arrived - Only 3%* of US AI users are willing to pay for it.
Technology1
-
Big Tech CEOs Spent Millions to Influence Trump and Republican Lawmakers, Attempting to Secure Billions in Tax Handouts Paid For By Ripping Health Care, Food From Families
Technology1
-
Iran’s internet blackout left people in the dark. How does a country shut down the internet?
Technology1
-
-
-
-