Comment by JoshTriplett

14 hours ago

Now if only these rulings also covered attestation.

Indeed. This ruling seems to be targeted at AI specifically. It is a great ruling, because it allows proper competition of other assistants with Google's (and Bixby). However, IMO the bigger evil is all the anti-competitive stuff that make it impossible for competitors to Android/iOS to enter the market, including European products like SailfishOS, such as remote attestation and the things that flow from it (e.g. no tap-to-pay support with most banks). The EC seems very pre-occupied with competition inside Android/iOS, while completely forgetting about competition between mobile OSes.

It is also pretty jarring to see the EU talk a lot about sovereignty, but then further entrenching the Android/iOS duopoly by baking remote attestation into the EUDI reference wallet (and copied into the national wallets), effectively shutting out alternative systems yet again.

Yes, I know that the EU consists of a lot of bodies and sometimes the right hand doesn't know what the left hand does. But man, sometimes I wish there was a stronger single, long-term vision. Somehow they seem to have forgotten about January this year (Greenland threats) and that as long as we fully depend on Android/iOS, etc. the US could shut down pretty much all modern communication infra. But instead of solving these vulnerabilities now and pouring money into alternatives, we (as the EU) drag ourselves down into battles of just how much we can do on the terrain of some feudal overlords.

It seems like there is a short window where we still have AOSP systems that could be workable for the large population (outside remote attestation, pretty much all apps run on GrapheneOS, microG, etc.) and Google's strong arming through developer verification and remote attestation could still be put back in the box. But the EC does nada, nothing (presumably).

  • I agree that attestation is the biggest deal. My current hope is that the upcoming GrapheneOS phones will be able to achieve that. It's really up to a manufacturer being able to strong-arm third-parties - banks and such - into accepting their chain of trust, and Motorola may be able to do that.

    • GrapheneOS doesn't solve the attestation problem though. If you compile it from source, the attestation still breaks (namely, you have to convince vendors that use attestation to trust your key). In practice, it does not allow you to run your code on your device anymore than stock Android with Google services does. At best, if GrapheneOS' build is reproducible, you can view the source code online and know that there isn't anything else in the blob you load onto your device

      Source-available isn't quite the same as having the software freedoms (use, study, modify, share) where you can modify the code or inspect what the various third-party apps are doing on your device. I can currently look into /data/data/any_app and modify preferences, view what telemetry is queued up, remove gigabytes of cache files... all that goes away with a GrapheneOS installation that passes attestation. They want to appear legitimate to app vendors and so comply with Google's rules about what data is accessible to users; otherwise, they'd never convince anyone to add their attestation keys to the allowlist. You need to be on a closed device before those vendors put you on the allow list (and you probably need to sell at least a million devices before they bother to consider you). The concept of attesting your phone is fundamentally antithetical to open source

    • I don't think the upcoming Motorola phones will change this by themselves. As far as I understand, Motorola will not directly sell GrapheneOS phones. They will make phones that fulfill the hardware requirements and work with the GrapheneOS team to make the firmware available, etc. It will still be up to the user to install GrapheneOS.

      That has benefits - you do not have to trust Motorola not to ship stuff that you wouldn't want in the image. They are pristine images that the GrapheneOS project provides. But it also probably doesn't get Motorola in hot water with Google, since they partially do the same as Google does (provide phones with unlocked bootloaders) and what Google used to do (open drivers, device trees, etc.). Plus there are other OEMs that have similar partnerships with other projects (e.g. Fairphone).

      into accepting their chain of trust

      It's GrapheneOS who will sign the images, not Motorola.

      Speaking of Europe, Motorola is probably not big enough here to strong-arm parties. Besides that, I don't think they will do that, since they have to stay in good graces with Google for distributing GMS Android.

      I think for Motorola, there are three wins: 1. GrapheneOS has hundreds of thousands of users now, for a smaller OEM capturing some of that market is a significant addition; 2. they want to have a security-focused offering; GrapheneOS can provide that; and 3. they probably want to strengthen their position towards Google. Samsung has their own app store, device finding ecosystem, etc., this tells Google - if you take too much power, we can go our own way. If the Motorola-GrapheneOS experiment is successful, this could provide a similar contingency plan that might hold Google from trying to reign in OEMs too much. This is a real risk for Google - Pixel is so small in terms of marketshare that if, say Samsung, would go on its own, Google Android is pretty much dead.

      At any rate, I think Motorola-GrapheneOS can have more of an indirect effect. I think Play Integrity remote attestation will fall if GrapheneOS can quickly get so many users that they become a force to reckon with. In the past, it helped when GrapheneOS users e-mailed an app developer that switched to strong Play Integrity. This will be much more powerful if the GrapheneOS user base grows 10x and more growth is probably possible if there are non-Google devices (especially because part of the potential user base does not want to give a cent to Google).

      Getting the EU to ban Play Integrity as-is probably has a much larger chance of succeeding though. This is why I always recommend people to file a DMA complaint/contact the DMA team when some app gets blocked on alternative ROMs due to Play Integrity. The DMA team needs to see/feel that this affects a lot of real people.

      4 replies →

  • Phone-tap-to-pay is not a real blocker. In fact I think it should be illegal for all vendors. Just use your physical plastic card. Stick it on the back of your phone if you like.

    • Phone tap to pay is really handy and provides more security than physical plastic cards. It should just not be used by Apple/Google to block out competitors.

      (Yes, I know banking apps can have their own tap-to-pay implementation on Android, but they all standardized on Google Pay because it's less work for them.)

      2 replies →

  • I mean EU have 20 years to make android/ios competition and they aren't able to replicate it so its them to blame

    also they should not abandon Nokia back then

    • The US has both infinite money for the rich and strong wealth inequality - both carrot and stick. I don't think it's a good way to live though. China also has unlimited money and top-down economic control that can direct good things to be made. Europe has neither. It has people with stable lives they don't want to mess up, and it has limited money, most of which is claimed by its existing billionaires through its bureaucratic processes.

      5 replies →

Android has an accessible hardware attestation API already (https://developer.android.com/privacy-and-security/security-...). It's what powers the attestation API that GrapheneOS made as an alternative to Play Integrity and friends (demo app: https://github.com/GrapheneOS/Auditor)

It's up to third party app developers to choose what library to use, of course. A court case between the EU and Google isn't going to chance anything about the verification steps apps like Netflix or your bank might use, that will have to be a separate case.

  • I personally have found great use from the little notifications that graphene OS pops up when the integrity API is accessed and it tells me the application. I saw Instagram accessing the integrity API probably entirely by coincidence while doing something in another app and so Instagram got immediately removed even though I never use it anyway.

    feel free to keep your why did you have Instagram on your graphene OS phone to yourself. I know. I know. I know. I know. XD

    and a little message when you tap on those notifications is exactly what the parent commenter stated encouraging users to contact app developers so that they can use basic integrity attestation and allow their apps to work on graphene OS.

    and some apps do work and use the integrity API. maybe a little too much in my opinion. chatgpt I'm looking at you. my local credit Union's banking app doesn't even bother with the integrity API and they updated their tech stack recently which included app redevelopment.