EU needs to take a stand on Play Integrity. If app devs enforce Play Integrity, this means only Google Certified devices can use banking, etc. This excludes all alternative mobile OS. No #postmarketOS, no #SailfishOS, no Android derivatives #GrapheneOS etc. You don't need Play Integrity. If someone is capable to install or use alternative OS, they sure know what to install or not install, it is on their responsibility. Using non-root but bootloader unlocked device (otherwise can't use alternative OS) does not make my device less secure. On the contrary, it is using an up to date OS with the latest security patches. Do we really want all mobile devices have to be Google Certified? No. #mobile #integrity #bootloader #unlocked #nonsense #Europe
@EUCommission is there any plan in motion to stop this monopoly from Google on Android? reCAPTCHA now also requires a Google Certified device status. Soon won't be able to use apps without being locked to Google.

@denzilferreira @EUCommission

Thankfully from what I see, the QR code verification in reCaptcha is a default option and user can change for visual or audio verification in one click. While the QR only is now used infernally in enterprises. At least for now.

@denzilferreira
I bet that Eu bureaucrats are instead really really happy about #PlayIntegrity since they gives them **apparent** total #censorship powers. Sadly I also bet they are too stupid to understand they are handling the keys of power to an evil entity overseas

@paoloredaelli I'm not sure I follow the reasoning behind EU wanting Play Integrity being a mandatory requirement for non Apple devices. Same way EU forced Apple to open their walled garden.

The only nuance thing here is, a Google Certified device means that they are running Google's proprietary blobs. So really, the course of action is, install alternative OS/use alternative OS and instead tell the devs of apps with Play Integrity checks that there are alternatives to check a device is not compromised - because that is what it should be about. Force Google to provide a different verification path that allows alternative ROMs/OS to be seen as safe.

@denzilferreira
I agree the whole line. But I'm also pessimistic and I won't be surprised discovering that EU politicians have been "financially facilitated" to endorse #Google way of controlling society. And those not oiled may be just fool enough to think that they can "control the dragon" and use Google infrastructures themselves to control the population

@paoloredaelli we don't know what we don't know šŸ˜‰ I trust we can elect EU representatives which share the same concerns. It is our responsibility to make sure of that if we want change. There are so many items that require attention, some more pressing than others. And we have the option of not using a smartphone at all šŸ™ˆ Banks are making their apps only work on such devices with Play Integrity, and closing bank offices. Soon, you can't check your balance, transfer, etc unless you have a smartphone that is certified (iPhone or Google Certified device).

Meanwhile, we can have an open dialog like we are having here, so that people around the world also think about what this actually means for them: no alternatives, no options, a monopoly.

@denzilferreira
> And we have the option of not using a smartphone at all

Not for long. At first you will not be able to pay for groceries. Finally not wearing a spying tag on you will immobilize you as a threat to the social order.

Technazis like sci-fi, just they don't like the endings.

https://en.wikipedia.org/wiki/In_Time

@paoloredaelli

In Time - Wikipedia

@denzilferreira
Luckily not all the banks are evilā„¢, for example I plainly refuse to work with banks that are not fully usable with a plain browser and no Android/iOS "certified" device
@denzilferreira eudi / wallet and everything eu related (w social) is full google service depending (all for security reasons...)
I dont think that they will change their mind
@sakura84 it's worth raising awareness that there are alternatives to Google Play Integrity, for example Promon Shield from Norway https://promon.io/products/shield-mobile, and many others. It definitely does not need to be a device that installs apps from the Play Store, and is GMS certified. F-Droid, Aurora Store work well on a deGoogled device but if the apps themselves don't work unless they detect that Play Store is installed, it means only Android with Google services can be used. No alternatives.
Promon Shield for Mobile: Always-on mobile app security | Promon

Promon Shield for Mobileā„¢ delivers post-compile, always-on protection against tampering, reverse engineering, and malware across all mobile apps.

@denzilferreira I seem to recall ā€œdon’t trust the client deviceā€ being drilled into my head over and over. Do bank app devs not know this? Are they lazy? Or both?
@WORM @denzilferreira From what I know it's a bit of both. They often use a skin over an existing software stack so they don't have to deal with as much regulatory details, even though that's kinda part of their job.
@denzilferreira I really want a way to export my private keys on the hardware that I own so I can fix the buggy software.

@denzilferreira
> EU needs ...

Do you realize that #technazi bros daily income is bigger than estimated life-earnings of the EU politicians of the past century, all of them?

Do we really expect EU politicians to resist this?

@ohir @denzilferreira Resistance is a tool of the well-paid?

@denzilferreira

No #postmarketOS, no #SailfishOS, no Android derivatives #GrapheneOS etc.

- No desktops either if Google's QR captcha is any indication of where we're headed. Assuming this goes through, even desktops will be locked out of the web unless they're linked to a Google device by scanning the QR captcha with said device.

Or, Google could mandate AluminumOS to be able to pass their captcha on the desktop as well, and only through the Chrome browser.

Worst case, the end game will be thin clients tied to rented servers, which would ultimately be tied to your government ID.