logoalt Hacker News

realusernametoday at 10:03 AM1 replyview on HN

Then it's a matter of personal opinion, I would not count any of the ones you listed as valid.

Integrity doesn't prevent customers to download a fake banking app, DRMs should be legally banned to be honest (sorry/not sorry media companies) and passports are best in physical form.

For company usage, locking the bootloader accomplishes the same thing.

As for bots, it doesn't prevent bots as you have unmodified device farms on racks. It's actually how ad fraud is done at the moment, they don't bother modifying the devices.

Pushing integrity even more will just funnel even more money to this ad fraud mafia as they will have a new source of revenue.


Replies

jeroenhdtoday at 10:18 AM

I, for one, like streaming apps enough that I don't want to go back to locked-down, expensive DVD players. The alternative to DRM isn't "no DRM", it's "no content".

Integrity detection means criminals cannot just inject some code into an existing banking app APK and call it a day. The hacked app won't generate valid HTTPS calls when properly validated. You can still phish users, but instead of automated online phishing panels, you need someone with a physical phone copying everything the user enters. It significantly raises the bar for these criminals.

If this stuff wasn't available, we just wouldn't have a lot of useful apps that we do today. The technology itself isn't bad per se, but the combination of a lack of hardware manufacturer support (for doing things like locking down bootloaders), custom ROM support (because bootloaders aren't locked down anyway), and app developer interest (see the whole GrapheneOS story) are what causes problems. Restricting the technology because the companies you deal with are shit is a bad solution in my opinion, because if they are motivated to be shit, they will find other ways to be shit.

For instance, someone set up an alternative attestation company that's even worse than Apple and Google, and if it weren't for Play Integrity, they'd be making the APIs and whitelists instead of Google.

show 2 replies