• cron@feddit.org
    link
    fedilink
    English
    arrow-up
    121
    ·
    4 months ago

    The site provides a nice TL,DR:

    • Efforts like Graphene OS face increasing pressure from apps that refuse to run on non-standard Android.
    • The custom ROM project characterizes Google’s approach to device attestation as incomplete and flawed.
    • Graphene OS is prepared to take legal action if Google won’t let it pass Play Integrity checks.
  • cron@feddit.org
    link
    fedilink
    English
    arrow-up
    62
    ·
    edit-2
    4 months ago

    On a personal note, I’m annoyed that our national ID app doesn’t work with graphene OS.

    There are workarounds by patching out the security check from the app and sideloading the newly created app, but that is just annoying and has to be repeated for every update.

    I just don’t see how rigorose device checks that lock out graphene users, but allow any Android 8.0+ device (where security support ended more than 3 years ago) make ANY sense.

    Edit: I tried it again today, it now lets me skip with a warning about the bootloader.

      • TheEntity@lemmy.world
        link
        fedilink
        English
        arrow-up
        24
        arrow-down
        1
        ·
        4 months ago

        Or frontdoor checkbox for that matter, given that it’s the literal device owner that takes the action tripping their “security” tripwire.

    • JustEnoughDucks@feddit.nl
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 months ago

      What national ID is it? I hope it isn’t the Belgian ItsMe app because I want to try putting lineage on my xperia 5 ii since it has a flaky fingerprint scanner now (software problem it seems)

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      10
      arrow-down
      10
      ·
      4 months ago

      “National ID app” sounds like something from 1984. I personally would never agree to something like that.

      • cron@feddit.org
        link
        fedilink
        English
        arrow-up
        9
        ·
        4 months ago

        I understand that even the concept is scary to some, especially to our friends on the other side of the atlantic.

        However, it isn’t really anything else than a 2FA app, similar to most banking apps. When you interact with a government service (like taxes, social security), you have to approve the login on your phone.

        • Possibly linux@lemmy.zip
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          9
          ·
          4 months ago

          Is it libre? Can I opt out and use physical ID? If the answer is no to any of those you shouldn’t use it.

          • cron@feddit.org
            link
            fedilink
            English
            arrow-up
            9
            arrow-down
            1
            ·
            4 months ago

            The app is not Libre, sadly. But it is possible to use a yubikey instead, then you need noting else than a web browser.

            Using physical ID is possible, but this would mean that I would need to walk to some office.

  • limerod@reddthat.comM
    link
    fedilink
    English
    arrow-up
    50
    ·
    4 months ago

    It’s high time Custom ROMs and users alike did this. I cannot run a custom ROM on my primary device due to play integrity shenanigans some apps may have.

  • 𝒍𝒆𝒎𝒂𝒏𝒏@lemmy.dbzer0.com
    cake
    link
    fedilink
    English
    arrow-up
    28
    ·
    4 months ago

    Looking forward to this. I don’t run a custom ROM myself but I am rooted, primarily to revoke permissions from Google apps and to back up my OS and app data as I desire.

    However I’d much prefer to be able to run something like GrapheneOS on a Pixel if it meant I could run apps that are picky about Safetynet/Play Integrity, such as banking apps and the like

  • sabreW4K3@lazysoci.al
    link
    fedilink
    English
    arrow-up
    21
    arrow-down
    2
    ·
    4 months ago

    Not gonna like. This is interesting. Who knew that messing with the ROM community could put Google in trouble.

      • sabreW4K3@lazysoci.al
        link
        fedilink
        English
        arrow-up
        2
        ·
        4 months ago

        I think you’d be surprised. CalyxOS are making massive claims. If the US or the EU investigate, Google could be fined or worse.

        • cron@feddit.org
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 months ago

          Seems at least plausible, given the whole “gatekeeper” regulations (EU).

  • rem26_art@fedia.io
    link
    fedilink
    arrow-up
    18
    ·
    4 months ago

    Device attestation is pretty annoying fr. It’s a constant game of cat and mouse to get it to work on a Custom ROM, whether its on the devs of the ROM, or whoever maintains the magisk modules if you’re rooted. I do hope things change about this

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      8
      ·
      4 months ago

      Honestly Lineage OS deserves some love. It can serve as both a daily driver and as a base for other systems. It could even been used by companies.

  • Possibly linux@lemmy.zip
    link
    fedilink
    English
    arrow-up
    14
    ·
    4 months ago

    It would be interesting to see if Graphene OS actually takes legal action. I hope if they do they get other projects involved including Lineage OS and maybe F-droid.

  • Azzu@lemm.ee
    link
    fedilink
    English
    arrow-up
    13
    arrow-down
    1
    ·
    4 months ago

    According to Graphene OS, the Compatibility Test Suite and Compatibility Definition Document requirements Google says are key to Play Integrity compliance are in practice routinely ignored, and the system easily bypassed.

    Just wanted to say, I use a custom ROM with software on it to circumvent the Play integrity stuff.

    Oh no, my device is insecure, there could be malware on it. But people use Windows PCs to access their banking website. I’m sure there can’t be any malware on PCs!

  • ArgentRaven@lemmy.world
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    2
    ·
    4 months ago

    I rooted my phone years ago and it was a chore. Once it finally worked, hardly any of my apps would run and nothing important worked because suddenly a rooted phone isn’t “safe”. It was such a pain in the ass to do updates and fight programs to run that I stopped. I didn’t want to spend hours fixing a device that I really didn’t want to think about.

    I would love to install GrapheneOS and have it mostly just work. I hate having my phone locked down like it’s not mine, and it’s one of the reasons I won’t use it for anything important over my desktop.

    • GeneralDingus@lemmy.cafe
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 months ago

      Most of my apps seems to work, surprisingly I don’t have an issue with my banking apps. However, I have run into issues with uhaul and ticketmaster apps.

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      4 months ago

      You don’t need Graphene OS (I had a different post about this)

      Any custom ROM without Google and with F-droid apps will be much better.

      • ArgentRaven@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        4 months ago

        Well, right, it doesn’t have to be a specific OS. I haven’t done much research because I’m my current situation, it’s not a good option for me as (for instance) some of my required 2FA apps won’t validate on a rooted phone.

        If that changes, I’d do more research, obviously.

  • shekau@lemmy.today
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 months ago

    Does anyone have experience with Fairphone? Im gonna buy new phone and need recommendation