← Back to context

Comment by inigyou

11 hours ago

> Getting the EU to ban Play Integrity

Unlikely to happen, it's just not how they operate. Instead they will create a government registry where any legal entity can register their integrity attestation keys, with oversight by a bureaucracy in a process that takes 6 months and €100,000. Apps will be required to use the registry but still allowed to block attestations they don't like, and any attestation key that leaks into open circulation (such as FOSS) will be blacklisted in the registry because it no longer attests anything.

any legal entity can register their integrity attestation keys, with oversight by a bureaucracy in a process that takes 6 months and €100,000

That wouldn't be great, but at the same time an improvement over the current situation.

attestation key that leaks into open circulation (such as FOSS) will be blacklisted in the registry because it no longer attests anything

Which makes sense if remote attestation is what you want.

  • Yes. It makes sense for well-regulated remote attestation. But is that what we actually want or do we want to destroy the concept altogether?

    • Exactly. There is no actual value provided by attestation that banks actually need. Banks have websites that work in web browsers, and those typically provide 99% of the functionality of the app, and yet the app demands attestation.