GrapheneOS's post on Mastodon discusses the flaws with Google's Play Integrity API

Open link in next tab

GrapheneOS (@GrapheneOS@grapheneos.social)

https://grapheneos.social/@GrapheneOS/112878067304840664

https://arstechnica.com/gadgets/2024/07/loss-of-popular-2fa-tool-puts-security-minded-grapheneos-in-a-paradox/ The article unfortunately leaves out most of the points we made in the thread. GrapheneOS supports hardware-based attestation and it's entirely possible for Google to allow it as part of the Play Integrity API. They choose to ban using GrapheneOS.

cross-posted from: https://lemmy.ca/post/26747543

The post is in the link, the article with more background info is here (it cites the mastodon post): https://www.androidauthority.com/custom-roms-vs-google-3469378/

I originally saw the article on this post on !android@lemdro.id and went looking for links.