GrapheneOS Threatens Legal Action Against Google [Android News Byte]

preview_player
Показать описание
The custom ROM Graphene OS is finding it difficult to work with Google’s approach to device attestation.

~~~~~

Mentioned Links
~~~~

Video Description
~~~~~
Good afternoon, everyone, and welcome to another edition of the Android News Byte.

#android #androidnews #grapheneos

Today, I wanted to highlight some controversy between a privacy and security focused custom ROM, Graphene OS, and Google.
Recently, it was discovered that Authy, a popular 2FA application, was no longer working on devcies that were using the custom ROM.

This was due to an update ot Authy that began using the Google Play Integrity API to see if a device was using modified software.
Meaning, if your phone is rooted. . .if you have a custom ROM installed. . .or even if you just have the bootloader unlocked
Then you are likely not passing Play Integrity checks.

And if you aren't passing Play Integrity checks. . .then some apps may choose to prevent you from using them.

Personally, I have the bootloader of my daily driver unlocked just in case the software bootloops.
This allows me the option to manually flash a fresh copy of the Android firmware to get things back up and running
But since the bootloader is unlocked, I am also failing the Play Integrity checks required to use apps like Authy

You can see how messed up the system is, yet Google claims there are no other options at the moment.
So even if you aren't using a custom ROM. . .or even if you aren't modifying the Android filesystem.
Google has no way of knowing if the OS is official, and they must assume it's bad.

However, things get a bit more spicy as GrapheneOS claims it has "irrefutable proof that the majority of certified Android devices" do not comply with Google's Compatibility Test Suite nor do they comply with its Compatibility Definition Document.

And then goes on to say that the "Play Integrity API is based on lies" due to the claim that Google allows devices from certain OEMs instead of banning them. They claim the system is unfair and that Google could easily work with custom ROM makers who follow the proper security guidelines.

The team says they have tried working with Google to get things up and running again.
Since GrapheneOS does have their own set of signed keys for the hardware they support. It seems like they should be able to get in contact with Google and make sure devices with their software have the correct keys in place.

Google claims these discussions are in place, however, they also state that it's "a lot of work on both sides" and that this will also include lawyers as well. They then end this discussion by saying their team is happy to help the custom ROM community, but higher-level support is tough because "modders are such a tiny, tiny fraction of the user base."

As of right now, GrapheneOS is in talks with regulators around the world. Hoping to get some additional support via laws that will force Google to put in the effort.

It's not like they don't have the funds to put toward something like this.

For now, many of us fear that more apps will begin using the Play Integrity API to prevent certain people from using the application.
I have read the Uber Driver app blocks this as well.
I would actually be curious to see a list of all the applications that are blocking these devices.

If you have noticed an application no longer works on your devcie due to Play Integrity API checks, let me know down in the comments section below.

And please, don't forget to like this video while also subscribing to the channel for more Android news content like this.

Summary
~~~~~~~~~~~~~~~~~
1. Intro [00:00]
2.

As an Amazon associate, I may earn a commission on sales from the links below.

The Gear I Use
~~~~~~~~~~~~~~~~~
Рекомендации по теме
Комментарии
Автор

I hope the best for the graphene team.

ImPipkinrick
Автор

This really is BS because the whole point of Android being open source like Linux you should be allowed to do whatever you want with it they have no right to do this crap and I hope they get sued for it because what's the point of an open source operating system if you just get penalized and punished for using it! 🤬🤬🤬🤬🤬

Sloff
Автор

Sandboxing google services limits their info scraping abilities, therefore hurting their profit margins. Google, meta, apple, etc. are all advertising agencies before anything else. They've just gotten rich enough to create entire data collecting operating systems to scale their profits further.

wakin
Автор

This is an interesting topic, and I hope the uploader (Explaining Android) does more of these informative videos about Graphene. I think interest will only grow, as privacy awareness continues to grow.

darenjones
Автор

Graphene isn't really a custom ROM. A) there's no "ROM" and ROM can't be programmed anyway, and B) Android itself is a custom version of Linux.
Graphene is it's own OS as much as Android is.

IaintTheHerb
Автор

My understanding is that the issue stems from the Play Integrity API being less robust than the hardware-based integrity checks supported by GrapheneOS (and PixelOS). The concern is that Google is using the Play Integrity API to unfairly limit which OSes are allowed, requiring them to bundle Google Play Services. This excludes some OSes, like GrapheneOS, that don’t break the security model and could even be considered more secure.

Fuzzzdaddy
Автор

The way you talk sounds **exactly** like @sideofburritos

davidyoder
Автор

I plan on switching to GrapheneOS. Should I wait for the Pixel 9 Pro or snag a Pixel Pro 8?

utubepunk
Автор

I'm still rocking my 6a with GOS. I freaking love it!

Menruleall
Автор

But why Authy and not a switch to Aegis ? Missing features?

Heroselohim
Автор

5th 3rd bank app quit when this happened and my bootloader is locked. I just made a web app icon and still do all my banking except for taking a picture to deposit a check. I noticed no other app hit by this.

backmore
Автор

if your phone gets stolen with an unlocked bootloader then the thief will be happy

alpacamale
Автор

All the same crap as Microsoft and stupid tpm.

MrBobWareham
Автор

having an unlocked bootloader is giving away all your personal data on your device in case it gets lost or stolen

Ali-gyzf
visit shbcf.ru