En god nyhed: Unified Attestation - et Google Play Integrity API alternativ er under udvikling, iniativ fra @volla og med deltagelse af blandt andet @murena!

https://uattest.net/

Brug det i din app, og fortæl din bank, mobliepay, digitaliseringsstyrelsen og alle mulige andre om det :-)

#engodting #opensource #alternative

Unified Attestation

Unified Attestation is a free, open-source alternative to Google Play Integrity with offline verification and simple app + server integration.

@anderslund @volla @murena Jeg kunne ikke lige se af linket, at Murena også deltager?
@bettina @volla @murena hehe, det kommer fra nicks (the linuxexperiement ) seneste video, hvor han omtaler det.
@anderslund @volla @murena Ok, tak! Jeg fik også et svar i murena-community men har ikke fået læst det endnu: https://community.e.foundation/t/article-paying-without-google/80205
ARTICLE: Paying without Google

Paying without Google: New consortium wants to remove custom ROM hurdles Using banking and payment apps on Android smartphones with custom ROMs is a problem: A European industry consortium now wants to change that. Full article here: Paying without Google: New consortium wants to remove custom ROM hurdles | heise online Regain your privacy! Adopt /e/OS the deGoogled mobile OS and online services

/e/OS community

@bettina @anderslund @volla @murena awesome: “With #UnifiedAttestation, we are creating a transparent and trustworthy procedure for security checks that developers and app publishers can rely on equally. This removes the last hurdle for the use of alternative mobile operating systems"
“We don't want to centralize trust, but organize it transparently and publicly verifiable. When companies check competitors' products, we can strengthen that trust," #unplugtrump #degoogle

https://www.heise.de/en/news/Paying-without-Google-New-consortium-wants-to-remove-custom-ROM-hurdles-11204037.html

Paying without Google: New consortium wants to remove custom ROM hurdles

Using banking and payment apps on Android smartphones with custom ROMs is a problem: A European industry consortium now wants to change that.

heise online

@MisterSmith @anderslund @murena To quote Voltaire quoting an Italian: "The best is the enemy of the good". Without having much technical insight, I think the initiative by Volla, Murena etc. is trying to fix a problem in a structure none of us created in the first place. So I welcome it.

Do I also want to see a world where tech is structured in a completely different way? Of course. But one step at a time.

And shaming others or wanting them obliterated is not a path to peaceful coexistence

@bettina @MisterSmith @anderslund Android already has a standard hardware attestation API which can be used to permit each of these options. The entire purpose of this system made by Volla, Murena and iodé is to centralize control over what's allowed to be use with a service under their control. The whole point of their service is to permit their own insecure products with no serious security standards while forbidding everything not part of it including GrapheneOS. It's definitely not legal.
@bettina @MisterSmith @anderslund Forming an anti-competitive cartel which pushes a centralized system only permitting using the products of the companies forming it while disallowing anything else is clearly not legal. We fully intend to file a lawsuit against Volla, Murena and iodé once the damages against GrapheneOS start building up. This highly unethical anti-competitive power grab by these companies will not stand. There's nothing peaceful about this aggressive power grab they're making.
@GrapheneOS @bettina @MisterSmith @anderslund I hope you'll file a lawsuit against Google that prevents me to use some apps (banks, mostly) on the system of my choice (i.e. not passing their integrity check), and soon will prevent me to install app from dev who does not want to give all their info to them (i.e. https://keepandroidopen.org/). If that's not anticompetitive cartel behaviour, I dont know what is.
PS : running GrapheneOS here
Keep Android Open

Advocating for Android as a free, open platform for everyone to build apps on.

@guilg @bettina @MisterSmith @anderslund We're already taking action against Google for the Play Integrity API. Volla, Murena and iodé have sided against us on freeing people from anti-competitive use of hardware attestation. Instead of fighting it, they've built their own anti-competitive system on top of the standard Android hardware attestation API. They've made it to permit their own products while forbidding others. It's clearly not legal and they don't have the legal resources Google does.
@guilg @bettina @MisterSmith @anderslund Google's developer verification system has no direct impact on GrapheneOS since we won't have any enforcement of that system. It's going to be a Google Play feature similar to Play Protect. App developers not performing verification would have grounds to file a lawsuit against them but we wouldn't since it doesn't directly negatively impact us. They've also said there will be a way around it for power users but not how that will work such as needing ADB.