72
you are viewing a single comment's thread
view the rest of the comments
[-] Crit@lemmy.wtf 5 points 4 days ago* (last edited 4 days ago)

There are basically 3 types of OSs out there:

  • Google-approved android (these come with Google apps, and most importantly Google services, which are basically what is going to BD doing the blocking for the cause Keep Android Open is concerned about. Google services already has some additional attestation stuff in, which many banks use, which only work if you've got a stock google-approved OS)
  • Non Google approved android (generally based on AOSP which is the actually open source code Google publishes for android, these don't come with google services so they fail the play store attestation, generally people will be needing microg to use stuff like YouTube, which is basically a light google services replacement)
  • Graphene OS (it gets its special category because it sandboxes apps so you can use Google services apps in a way that doesn't give them access to the rest of your system and therefore shouldn't be able to mess with what you want to install, best of both worlds but it's not foolproof).

There are a few other projects like /e/ but that's just AOSP with a coat of paint, graphene is a much more substantial change to how your phone locks down app access.

[-] MonaySimpson@lemmy.ml 1 points 2 days ago

Yes. But the dev lockout stuff that Google is forcing will apply to all three. As I understand it.

[-] Crit@lemmy.wtf 1 points 2 days ago

It works through the Google play services afaik so it won't.

[-] MonaySimpson@lemmy.ml 1 points 2 days ago

Thanks.

It seems that

The rule only kicks in on devices that come loaded with Google's own apps and services, known as Google Mobile Services or GMS.

That said, LineageOS flagged one gap worth watching which is if someone sideloads a third-party Google Apps package onto their device, that package could theoretically include the verification system bundled in

I wonder of we'll see more banking (and other) apps lockout ROMs that don't have GMS, or bundle it in when installed on something like gOS.

[-] AlteredEgo@lemmy.ml 2 points 4 days ago

So does microG work good enough to run banking apps? That's really the big question for most I think.

[-] timbuck2themoon@sh.itjust.works 3 points 3 days ago

You use the plexus app to find out essentially. Can be installed from fdroid.

[-] AlteredEgo@lemmy.ml 2 points 3 days ago

Thanks. Well surprisingly even banking should be working, except one "broken" review for the latest version.

[-] Crit@lemmy.wtf 1 points 4 days ago

Not really cause you need to patch those apps to support microg instead afaik, at least you do with YouTube, and banking apps probably have ways to check if they've been meddled with.

To expand on that if you're curious, there are afaik 2 types of attestation to verify it's a safe device, device attestation (which checks for a locked bootloader and some specific fingerprints), this is safe to fake for custom roms. The other one is the one i mentioned done through the software side with Google play services and such. That's impossible to fake currently (afaik, been a minute since I could install a custom rom).

[-] AlteredEgo@lemmy.ml 1 points 3 days ago

Thanks. What a shame. I blame the banks really.

[-] Crit@lemmy.wtf 2 points 3 days ago

It's really Google's fault for implementing this, the banks do get some of the blame for using it too when it has nothing to do with security though.

this post was submitted on 21 Aug 2026
72 points (96.2% liked)

Android

34612 readers
1104 users here now

DROID DOES

Welcome to the Android community on Lemmy. Here you can participate in amazing discussions and events relating to all things Android.

The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:

Rules


1. All posts must be relevant to Android devices/operating system.


2. Posts cannot be illegal or NSFW material.


3. No spam, self promotion, or upvote farming. Sources engaging in these behavior will be added to the Blacklist.


4. Non-whitelisted bots will be banned.


5. Engage respectfully: Harassment, flamebaiting, bad faith engagement, or agenda posting will result in your posts being removed. Excessive violations will result in temporary or permanent ban, depending on severity.


6. Memes are not allowed to be posts, but are allowed in the comments.


7. Posts from clickbait sources are heavily discouraged. Please de-clickbait titles if it needs to be submitted.


8. Submission statements of any length composed of your own thoughts inside the post text field are mandatory for any microblog posts, and are optional but recommended for article/image/video posts.


Community Resources:


founded 3 years ago
MODERATORS