GrapheneOS implemented a new system to battle Play Integrity API

We’ve implemented a system for notifying users when apps use the Play Integrity API. This will help users determine which apps are banning using a non-stock OS. Some of these will still work if they only enforce basic integrity rather than requiring a Google certified device running the stock OS.

Using Play Integrity is an incredibly anti-privacy and anti-security practice despite being wrongly portrayed as a security feature. The notification will include a link for leaving a rating and review for the app via sandboxed Play Store to make it very convenient for people to send complaints.

16 Likes

They also seem optimistic that the EU Commission will take action against Google sooner rather than later.

https://xcancel.com/GrapheneOS/status/1877794672547897539#m

There’s no valid reason this should be the case and we intend to get this problem solved. EU Commission contacted us about it over a year ago and is well into the process of starting to deal with it now. We expect it’s going to be dealt with and Google will face consequences.


They are still investigating whether to implement a per-app toggle to block Play Integrity API requests.

https://xcancel.com/GrapheneOS/status/1877900471584612776#m

We may also add a way to block the Play Integrity API with a per-app toggle if we determine this helps improve compatibility due to some apps still having a fallback to other approaches. Spoofing device integrity level is possible but increasingly problematic and will get worse.

10 Likes

I’d really like to know what’s happening behind the scenes.

2 Likes

Me too. It is very exciting to see GrapheneOS standing up to Google and hopefully affecting meaningful change.

I am a bit concerned by the news that the EU is reassessing tech probes into Apple, Google and Meta.

2 Likes