# A Data-Driven Evaluation of the Current Security State of Android Devices

**URL:** https://discuss.privacyguides.net/t/a-data-driven-evaluation-of-the-current-security-state-of-android-devices/22362
**Category:** General
**Created:** 2024-11-12T13:23:45Z
**Posts:** 15

## Post 1 by @sha123 — 2024-11-12T13:23:45Z

Great work again from Mayrhofer et al: “A Data-Driven Evaluation of the Current Security State of Android Devices”. Contains a research paper, crowd-sourced table of hardware and an app for evaluation and contributing:

> **[René Mayrhofer :verified: 🇺🇦 (@rene_mobile@infosec.exchange)](https://infosec.exchange/@rene_mobile/113431029855652363)**
>
> Happy to report public availability of a new paper "A Data-Driven Evaluation of the Current Security State of Android Devices" at the IEEE CNS 2024:...

According to this table, Google Pixels beat other devices listed there by far. Even Samsung S-series doesn’t look good.

---

## Post 2 by @anon48875053 — 2024-11-12T13:33:26Z

> [@sha123](#):
>
> According to this table, Google Pixels beat other devices listed there by far. Even Samsung S-series doesn’t look good.

What a surprise! /s

---

## Post 3 by @anon48875053 — 2024-11-12T14:35:00Z

I downloaded their app and it looks like they require devices to be Google certified, yikes.

---

## Post 4 by @sha123 — 2024-11-12T14:51:00Z

They probably need attestation so they can be sure that results haven’t been tampered with.

---

## Post 5 by @anon48875053 — 2024-11-12T14:53:51Z

I’m not talking about MEETS\_BASIC\_INTEGRITY, MEETS\_STRONG\_INTEGRITY or them using hardware attestation like GrapheneOS recommends. They’re asking for MEETS\_DEVICE\_INTEGRITY which is basically a blessing from Google and nothing more.

---

## Post 6 by @sha123 — 2024-11-12T15:07:15Z

Feel free to contact Rene, e.g. on Mastodon. I wrote with him in the past and he seems like a nice guy and is a great expert in Android security. Maybe he can do something about changing this requirement.

---

## Post 7 by @anon48875053 — 2024-11-12T15:14:42Z

Just sent him a message.

> Hi, this app requires devices to pass MEETS\_DEVICE\_INTEGRITY. To pass it, your OS needs to be certified by Google which makes this check just a blessing from Google and nothing more.
> 
> Other two checks are fine, but the proper way to audit the integrity of the devices is docummented here: [Attestation compatibility guide | Articles | GrapheneOS](https://grapheneos.org/articles/attestation-compatibility-guide)
> 
> Android’s hardware attestation API is a lot more robust form of attestation than Play Integrity API and doesn’t require OSs to be certified by Google, which is anti-competitive.

---

## Post 8 by @phnx — 2024-11-12T16:00:25Z

This wasn’t my experience. The app worked perfectly fine for me on a GrapheneOS device (with sandboxed play services), although I did not attempt to upload the results.

---

## Post 9 by @anon48875053 — 2024-11-12T16:04:18Z

They require certification to upload the results.

---

## Post 10 by @sha123 — 2024-11-12T16:10:06Z

Did you know he is not only the ‘head of the Institute for Networks and Security’ at a university in Austria, but also the ‘Director of Android Platform Security at Google’?

I hope you don’t mind, but considering this, the way you phrased your message, made me giggle a bit :slight_smile:

---

## Post 11 by @phnx — 2024-11-12T16:22:57Z

Thanks for clarifying, that is indeed unfortunate.

---

## Post 12 by @anon48875053 — 2024-11-12T16:30:42Z

That check is just circus, and I think he knows it, at least I hope so.

Anyway, GrapheneOS is in contact with EU regulators and with a company that would help them file a lawsuit to put this Play Integrity circus to an end.

---

## Post 14 by @phnx — 2024-11-16T18:00:00Z

At first, this seemed like a cool project, but unfortunately, many of the results are plain nonsense. The Pixel 6 is given a score of 94.91 as a ‘secure device,’ while the Pixel 9 Pro gets a 79 and is considered ‘insecure’?

After some testing, the issue is due to outdated information pertaining to devices in their database, particularly relating to patch level, which (rightfully) weighs very heavily.

I really wouldn’t recommend this tool to anyone who is trying to evaluate and/or compare device security, since their database is outdated, their site is unhelpful at best and misleading at worst.

---

## Post 15 by @sha123 — 2024-11-16T18:41:33Z

Outdated patch level information is indeed a problem. Nevertheless it can still be useful, for example to lookup and compare hardware security features of different devices.
