• kbal
    link
    fedilink
    658 months ago

    The key difference between “Android’s Play Integrity API” and this new thing which they are no longer proposing to put in Chrome but into Android WebView instead is the remote part of “remote attestation”.

    The article does not make it entirely clear, but the new thing looks to be exactly the same as the old Web Environment Integrity we knew and hated, but with a new name and temporarily exclusive to Android.

    • @BearOfaTime@lemm.ee
      link
      fedilink
      English
      128 months ago

      I’m so glad there are devs behind things like Lineage, DivestOS and Graphene. I’m currently setting up a oh one using Divest without Google.

      I’ll be buying some Pixel 5’s to get me through the next 5 years (my current phones are from 2018, and really fast with Lineage or Divest, and load a bunch of apps, and automation).

  • Keith
    link
    fedilink
    English
    588 months ago

    As someone who uses root (not at the moment but plans to) as I believe in owning my devices, fully, this is horrible. We still need to oppose this.

    • LiveLM
      link
      fedilink
      English
      41
      edit-2
      8 months ago

      I know right? The article touches on this:

      Google said the inspiration for the original Web Integrity project was Android’s Play Integrity API, which already scans your phone for root privileges and denies access to things

      ^^^ this should have never, ever been a thing!

      • @0xD
        cake
        link
        English
        -48 months ago

        That is just standard and a completely sensible security measure for preventing people from tampering with an application. It cannot replace proper, server-side security measures but is a big step. Especially for stuff like banking applications.

    • @SkyeStarfall@lemmy.blahaj.zone
      link
      fedilink
      English
      208 months ago

      The problem with root is that banking applications and many others straight up actively try to detect it and refuse to work if you are rooted. Android is in the process of being completely locked down.

      • @limerod@reddthat.com
        link
        fedilink
        English
        198 months ago

        Not just root. Some even detect if you have usb debugging enabled and warn or refuse to work unless you turn that off.

        • @limerod@reddthat.com
          link
          fedilink
          English
          38 months ago

          What’s the workaround for apps detecting usb debuging or other user apps on your device? I’m not rooted, but use shizuku and WiFi adb for certain features on my android.

        • @SkyeStarfall@lemmy.blahaj.zone
          link
          fedilink
          English
          2
          edit-2
          8 months ago

          Last si rooted there were also workarounds, but they didn’t always work, relying on the workarounds being updated to fight ever more advanced detection methods. It was a cat and mouse chase.

          • @glorious_puffy@lemmy.world
            link
            fedilink
            English
            18 months ago

            Apps I use work fine with vanilla magisk. If there are apps detecting root even after enabling zygisk, use magisk delta and enable magisk hide

        • @Pips@lemmy.sdf.org
          link
          fedilink
          English
          18 months ago

          The biggest continuing issue is NFCs, which will require people to accept that non-stock OSes are perfectly fine.

      • sadreality
        link
        fedilink
        48 months ago

        Switched to web browser…

        These apps are fucking obnoxious.

        Google wants you to pay for hardware but they get to control it because they can’t trust you lol

        • @BearOfaTime@lemm.ee
          link
          fedilink
          English
          28 months ago

          Yep, never have a root issue if you access a baking service via a browser.

          And with apps like Hermit you can make a web page very app-like.

  • RooPappy
    link
    fedilink
    35
    edit-2
    8 months ago

    Big fucking sigh. I’ve been an Android user since the T-mobile G1, and I have ferociously defended the platform against iPhone for that entire time.

    Is there a 3rd option? Or do I have to learn to love the enemy? I won’t be a part of the problem with privacy just because I’m too lazy to change.

    • @BearOfaTime@lemm.ee
      link
      fedilink
      English
      198 months ago

      Use Graphene, Lineage or DivestOS (fork of Lineage) . Graphene and Divest enable you to sandbox all Google BS if you need it, and Dos uses their own we view from Mull.

      • RooPappy
        link
        fedilink
        48 months ago

        I love the idea, and would be willing to be an early adopter of a linux phone… but its tough to give up application support.

      • RooPappy
        link
        fedilink
        15
        edit-2
        8 months ago

        Because Apple are: closed system, unrepairable, proprietary, refuse to adopt standards, elitist and exclusionary, and generally less flexible and customizable. They are a baby toy, they are any recent BMW, and they are jerks about it.

        And somehow, that’s becoming the better option over thieves and scammers with bad intentions. I may have to go with the assholes over the bastards. It doesn’t feel great.

        • @jol@discuss.tchncs.de
          link
          fedilink
          English
          -28 months ago

          I get you, but calling iOS a toy just makes you sound childish and ignorant. I don’t use apple for the same reasons, but iOS right now offers by far the most polish, mature and thought-through experience. In the meantime, Android continues to change everything on a whim every couple versions to nonsensical defaults. The UI keeps getting worse.

          But I just can’t stand the inability of customizing iOS. Google is strangling the platform, replacing FOSS features with Google counterparts, and if it wasn’t for Samsung and maybe a few other big ones, they would probably have abandoned AOSP by now.

          • MaggiWuerze
            link
            fedilink
            English
            48 months ago

            iOS right now offers by far the most polish, mature and thought-through experience

            If you want to do it exactly as they allow you to. Everytime you try to deviate from Apples happy path there are suddenly thorns everywhere and you find yourself without any support, be it on iOS or MacOS

    • ares35
      link
      fedilink
      58 months ago

      google has been on the dark side since before “don’t be evil” was even associated with the company.

      • @BearOfaTime@lemm.ee
        link
        fedilink
        English
        18 months ago

        The first time I heard “don’t be evil” all I could think is why do you have to say it?

    • @bobbytables@feddit.de
      link
      fedilink
      English
      37
      edit-2
      8 months ago

      Google is killing off its proposal for “Web Environment Integrity API” as a new web standard, though Android phones may still have to deal with it.

      That is literally the first sentence of the linked article. I think this is one of the things how it comes back.

      • @SHITPOSTING_ACCOUNT@feddit.de
        link
        fedilink
        English
        3
        edit-2
        8 months ago

        Does Vanced really use WebView for playback (the link the article provides suggests it’s used for sign-in)?

        Aside from forgetting to mention Revanced which is very much alive, I have doubts about the article. It feels like the author realized his headline doesn’t work anymore so came up with something plausible sounding…

        • ChaoticNeutralCzech
          link
          fedilink
          English
          6
          edit-2
          8 months ago

          Vanced and Revanced use(d) a fork of MicroG for sign-in. MicroG is a FOSS implementation of Google Play Services and other Google app APIs but with minimum tracking. It uses the website to sign in, which I imagine is rendered with WebView because the app is so small.

          • IggyTheSmidge
            link
            fedilink
            38 months ago

            Yeah, I’m running LineageOS with MicroG, so I tried disabling Android System Webview as a test. ReVanced seems perfectly happy to browse/play videos (though I didn’t try logging out). The only apps I have that fall over without webview seem to be eBay and Amazon, so no great loss there.

            • ChaoticNeutralCzech
              link
              fedilink
              English
              48 months ago

              MicroG can run in background without WebView, only logging in requires the website-based GUI.