#playintegrity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #playintegrity, aggregated by home.social.
-
One interesting part to bypass Play Integrity, by Quarkslab: https://blog.quarkslab.com/bypassing-android-hardware-attestation.html
The 2nd part is a live LPE to spoof calling app package Id and signing key - many LPE already exist, the hooks have to be done
-
Another one bits the dust. #patreon #playintegrity #google #gos
-
It seems like Google Play Integrity Basic is broken with microG, even though I'm connected with my Google account. I know Google introduced App Licensing checks at some point, but it no longer seems to be evaluated.
-
@nfk
Hoffentlich macht das BSI die Play Integrity nicht eine Voraussetzung für "sicher".Denkt ihr es macht Sinn, dem BSI dazu mal zu schreiben? Vlt sollte die Zivilgesellschaft auf den Prozess hier mehr Einfluss nehmen?
@Lilith @max @PersonOfInterest @KonstantinNotz#Google #PlayIntegrity #Android #Apple #iOS #appattest #EUDI #Security #Wallet #App #Digitalisierung #wallet #id #authentication #bmi #eu #datenschutz #BSI #Sprind #EUDION2026
-
@nfk
Auf der EUDI On 2026 Konferenz gestern gab es diese Neuigkeit:Die Sprind hat die EUDIW für die Zertifizierung / Pentatesting beim BSI erstmal ohne Abhängigkeit auf Play Integrity eingereicht.
Sollte es durchgehen bleibt es bei der Version ohne Google. Wenn das BSI nein sagt, wird es wieder eingebaut.
#Google #PlayIntegrity #Android #Apple #iOS #appattest #EUDI #Security #Wallet #App #Digitalisierung #wallet #id #authentication #bmi #eu #datenschutz #BSI #Sprind #EUDION2026
-
@celenity @mozilla @firefoxnightly
OK, found the patches. As you said Mozilla has introduced Play Integrity dependency for their AI thing (MLPA).
And they use it only for "authentication" - something that can easily be done with the hardware attestation API - that's depressing
It deserves some visibility, I hope they will step back. Nobody should use the Play Integrity API
-
Usługi Google Play. Uzurpator na tronie-smartfonie
Dobrze napisany artykuł opisujący przystępnym językiem monopolistyczne zapędy Google z ich Usługami Google na czele. Co prawda temat wałkowany w fedi od jakiegoś czasu, jednak i tak gorąco polecam lekturę od Ciemnej Strony.
https://www.ciemnastrona.com.pl/google/2026/06/03/uslugi-google-play-ciemne-strony
-
Recommendations by the EU commission. As mentioned in the document, the so called "Architecture and Reference Framework" should "serve as a basis" for all EU countries implementing the e-wallet (see amended eIDAS regulation, "eIDAS 2.0").
So the basis, regardless of what different EU countries decide, is to have the app locked in the mobile phone duopoly of operating systems, Apple and Google. (Which will automatically include the so called Play Integrity API.)
"6.5.2.2 Wallet Solution authenticity is verified
To ensure that the User can trust the Wallet Solution, Wallet Providers preferably make their certified Wallet Solutions available for installation via the official app store of the relevant operating system (e.g., Android, iOS)."
https://eudi.dev/2.8.0/architecture-and-reference-framework-main/
-
CW: Google's New Monopoly Over the Web (re: reCaptcha & Play Integrity)
Wait, so reCaptcha can now require that you have an iPhone or an Android phone with Google Play Services?
This is really really bad. :neocat_sad: And, what's worse, is it seems nobody is talking about it.
For anyone unfamiliar, Apple's App Attest and Google Play Integrity are "hardware attestation" which uses a hardware lockout to verify that you device is 'valid' and not tampered with. It sounds like good security in theory, until you think about it for more than two seconds. It effectively means that, in order to have a 'valid' device, you need to be approved by either Apple or Google. As such, it doesn't work with non-Google Android ROMs like GrapheneOS, /e/, LineageOS, etc. Once your device isn't considered valid by Play Integrity it locks you out of hundreds of apps, effectively giving Google complete monopolistic control over Android.
This change to reCaptcha brings that same monopolistic control to the web. If you thought you could be above the Apple/Google duopoly in some way, congratulations, it's officially impossible. You have to own a Google Play-certified phone or iPhone in order to use the internet in 2026.
For anyone hoping the European Union will step in, I wouldn't hold your breath.
-
Good to see a POC that shows how useless security-wise is the Play Integrity:
Android LPE using DRAM bitflip => https://bsky.app/profile/retr0.id/post/3mljtyauw322d
A requirement to get any security protection with the Play Integrity is that attackers can't bypass it on any device.
As soon as an attacker can bypass it, it is possible to distribute app clones (fake banking app) that proxy-pass the Integrity requests to a controlled device, defeating the Play Integrity.
On the other side, how many users are locked-out of critical services because of the Play Integrity? For legit users, any non-trivial workaround is a blocker.
Play Integrity is not about security, but about coercition, Google's tool to impose their conditions: eg. forcing OEM to preinstall their apps, some with privileges (Chrome, Youtube, Play Services, etc)
-
CW: Rant / Banking+Root / App-Zwang
Hatte das Thema die Tage schon. Hat mich halt Zeit gekostet für vglw. ernüchterndes Ergebnis 😶
Banken mit TAN/ #OnlineBanking ohne #AppZwang muss man suchen.
Würde gerne solche Annehmlichkeiten wie Bezahlen mit dem Handy nutzen, oder #AndroidAuto. 👀 Aber halt datensparsam. 💁Hab intensiv versucht die #PlayIntegrity auszutricksen. Zwecklos 🥲
Install mehrerer #Magisk Module. Dann sowas: Öffnet Link zu #Telegram Channel, gehst zurück und siehst das am Log-Ende 😵 -
RE: https://wolnoscwkieszeni.pl/unified-attestation-europejski-odpowiednik-play-integrity/
Po dłuższej przerwie na blogu wylądował nowy wpis o Unified Attestation.
Jest to europejski odpowiednik Play Integrity, czyli centralny system atestacji urządzeń. Ta inicjatywa producenta smartfonów Volla jest promowana jako uniezależnienie się od Google. Jednak czy uniezależnienie się od jednej korporacji ma polegać na uzależnieniu się od innej?
Temat dość istotny z punktu widzenia niezależności i konkurencyjności mobilnych systemów operacyjnych, a nie zauważyłem żeby przebił się do polskich internetów.
Ps. Kto znajdzie w tekście easter egga? 😉
#unifiedattestation #playintegrity #volla #murena #eos #iodeos #grapheneos #android
-
Unified Attestation – Europejski odpowiednik Play Integrity.
Ostatnimi czasy w wolnym (as speech, not as turtle ;) ) internecie dość mocno wrze, głównie za sprawą działań, które śmiało możemy nazwać zamachami na naszą prywatność. Najgłośniejszym echem odbijają się tematy domykania Androida przez Google, czy powracający jak bumerang Chat Control. W całym tym zgiełku mógł nam umknąć pomysł stworzenia europejskiego odpowiednika Play Integrity. Unified Attestation, bo o nim będzie mowa, to inicjatywa europejskiej firmy Volla przy współpracy Murena (/e/os) oraz iodé.https://wolnoscwkieszeni.pl/unified-attestation-europejski-odpowiednik-play-integrity/
-
Ohne #Google #PlayIntegrity auf #Android oder ohne #Apple #iOS #appattest funktioniert das #EUDI-Wallet nicht.
Das heißt doch, versierte Entwickler*innen, denen #Security wirklich wichtig ist, werden kaum Anwendungen bauen, die mit dem #Wallet des @bmi arbeiten, oder?
Also: insgesamt werden die Bürger*innen künftig eher weniger starke IT-Sicherheit auf dem #App Markt finden, oder?
Ist das denn das Ziel der @Bundesregierung, hat sie irgendwie Angst vor Bürger*innen, die ihre Daten gut schützen können? 🤔
#Digitalisierung #wallet #id #authentication #bmi #eu #datenschutz
-
@manuel il problema non è #Jolla. Il problema è proprio #AppIO che non dovrebbe esistere in questa forma:
1) non dovrebbe richiedere #PlayIntegrity
2) non è riproducibile/ricompilabile quindi è di fatto #SoftwareProprietario e #softwareprivativo
3) dovrebbe poter girare "ovunque": #Linux #BSD, #haiku eccetera
Per come è implementato #noAppIO
Lo stesso vale per app di banche e CieID -
On the topic, #GrapheneOS allows to install the official PlayServices, Playstore and ServicesFramework.
These run with a compatibility tool called #GMSCompat and if this tool grants them the required privileged permissions.
So GCam should work fine, it just got a ton more invasive. #Enshittification
Apps run fine without elevated permissions, but #Google doesnt care to build their apps following the #Android security model. So they require crazy deep access to things, as they are too lazy to make a permission for that.
Meanwhile Google is locking down user app permissions further and further (breaking things like #Syncthing), while leaving out essential permissions like the ones GrapheneOS adds (network permission, storage scopes, contact scopes, sensors) to fuel their tracking business.
And systems without basically backdoors (proprietary system apps that bypass the Android app sandboxing model... by not using it) are not Play Certified and apps using #PlayIntegrity will refuse to run on them. FOR SECURITY!
They refuse to run on systems without backdoors!
(Little side tangent but this just strengthens how ironic Google is)
-
Un ejemplo de app que usa la #PlayIntegrity para banear SOs Android no licenciados por Google, porque esta app funciona perfectamente en PixelOS.
Renfe contribuyendo al monopolio de Google, triste.
-
Na stronie GrapheneOS pojawiła się nowa sekcja z listą aplikacji, które celowo odmawiają działania pod tymże systemem. Są to aplikacje, które sprawdzają kompatybilność z zależnym od Google 'Play Integrity API' (zamiast bezpieczniejszej sprzetowej atestacji androida) i w przypadku jego braku odmawiają uruchomienia. Twórcy GOS zachęcają do pozostawienia w sklepie Play adekwatnych opinii.
https://grapheneos.org/articles/attestation-compatibility-guide#apps-banning-grapheneos
#playintegrity #playintegrityapi -
Cholera jasna, Gógiel znowu coś nazmieniał w wykrywaniu zrootowanych telefonów i mimo rozmaitych kombinacji z modułami Magisk, dzięki którym checker pokazuje, że telefon przechodzi wszystkie testy, Portfel Google odmawia działania.
-
Today is the day bootloader unlocking and rooting dies. It's over. It's so fucking over.
#android #google #googleplay #playintegrity -
@GrapheneOS I just installed Revolut app version 10.76.1 on my Pixel 9a with GOS and had no problems with play integrity, whether they removed the check silently?
-
Qualcuno usa #revolut su ROM non stock? Su una #lineageos #microg con #root e #playintegrity fix ora mi da errore dispositivo con root ed ho anche fatto nascondi app root e messa sulla lista blocco 🤷🏻♂️😤😤 non so più che fare 😭😭! #android #magisk #help #mastoaiuto #boost #boostme
-
#mastoiuto che moduli usate per fixare #playintegrityapi io uso il modulo di chiteroma ma sembra abbia bisogno anche di questo https://github.com/5ec1cff/TrickyStore #android #playintegrity