Comment by jeroenhd

11 hours ago

Android has an accessible hardware attestation API already (https://developer.android.com/privacy-and-security/security-...). It's what powers the attestation API that GrapheneOS made as an alternative to Play Integrity and friends (demo app: https://github.com/GrapheneOS/Auditor)

It's up to third party app developers to choose what library to use, of course. A court case between the EU and Google isn't going to chance anything about the verification steps apps like Netflix or your bank might use, that will have to be a separate case.

I personally have found great use from the little notifications that graphene OS pops up when the integrity API is accessed and it tells me the application. I saw Instagram accessing the integrity API probably entirely by coincidence while doing something in another app and so Instagram got immediately removed even though I never use it anyway.

feel free to keep your why did you have Instagram on your graphene OS phone to yourself. I know. I know. I know. I know. XD

and a little message when you tap on those notifications is exactly what the parent commenter stated encouraging users to contact app developers so that they can use basic integrity attestation and allow their apps to work on graphene OS.

and some apps do work and use the integrity API. maybe a little too much in my opinion. chatgpt I'm looking at you. my local credit Union's banking app doesn't even bother with the integrity API and they updated their tech stack recently which included app redevelopment.