EU needs to make a stand on Play Integrity. If app devs enforce Play Integrity, this means only Google Certified devices can use banking, etc. This excludes all alternative mobile OS. No #postmarketOS, no #SailfishOS, no Android derivatives #GrapheneOS etc. You don't need Play Integrity. If someone is capable to install or use alternative OS, they sure know what to install or not install, it is on their responsibility. Using non-root but bootloader unlocked device (otherwise can't use alternative OS) does not make my device less secure. On the contrary, it is using an up to date OS with the latest security patches. Do we really want all mobile devices have to be Google Certified? No. #mobile #integrity #bootloader #unlocked #nonsense #Europe
@denzilferreira I seem to recall “don’t trust the client device” being drilled into my head over and over. Do bank app devs not know this? Are they lazy? Or both?
@WORM @denzilferreira they're on team "an intern found this function that ensures everything's super duper secure, so we're a-ok"