this post was submitted on 29 Jul 2023
1258 points (98.1% liked)

Technology

59559 readers
4137 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

I'm happy to see this being noticed more and more. Google wants to destroy the open web, so it's a lot at stake.

Google basically says "Trust us". What a joke.

you are viewing a single comment's thread
view the rest of the comments
[โ€“] [email protected] 6 points 1 year ago (1 children)

It's a bit worse than just Google libraries, apps can use Play Integrity which uses hardware attestation to validate it's bootloader lock status and that it's running a vendor signed and Google approved ROM.

Current bypasses emulate older devices without the necessary hardware, but those will eventually stop working and there won't be bypasses unless someone leaks some master keys or finds TPM exploits to trick it into signing the integrity request. It's very bad.

[โ€“] [email protected] 3 points 1 year ago

Yes, but they're two separate issues. Many apps that don't care whether you have root or a third-party Android build use Google's libraries.

Patching apps is another workaround. It won't beat server-side checks, but I think those are still fairly rare. ReVanced makes it easy to do, though I'm not sure there are patches related to SafetyNet yet.