• chameleon@fedia.io
    link
    fedilink
    arrow-up
    5
    ·
    13 hours ago

    I haven’t seen proper reporting but the Play Integrity install source thing is accurate. There’s a reasonably good overview straight from the devil himself.

    Lots of things that have very valid reasons on paper that also just happen to give Google a stupid amount of control and will backfire for a somewhat small percentage of people in very bad ways. We’ve been at “you can’t use pretty much any bank unless you agree to either Google or Apple terms” for quite some years now, now we’re giving those same app developers ways to detect if their device has accessibility APIs enabled (useful to protect against bot farms, but also a functional check for “you’re able-bodied”) or is in security support (also a functional check for “not reliant on hand-me-downs”).

    • masterofn001@lemmy.ca
      link
      fedilink
      English
      arrow-up
      2
      ·
      7 hours ago

      Lol. So this API for ‘security’ and ‘integrity’ basically has a built in malware trojan:

      Avoid caching integrity verdicts Caching integrity verdicts increases the risk of proxying, which is an attack where a bad actor reuses a verdict from a good device for abusive purposes in another environment. Instead of caching responses, you can make a standard API request to get a verdict on demand.