Hacker News new | ask | show | jobs
by bilkow 371 days ago
We do, but I don't see it happening anytime soon. Many banking / government apps and even some games use the Play Integrity API, which AFAIK is starting to require remote attestation for newer devices.

As it's usually not viable to opt-out of those, the solution seems to be having a separate device.

1 comments

Fortunately (or unfortunately depending on your perspective), Play Integrity is bit of a joke at the moment thanks to a group of OEMs who just can't seem to secure their private keys. Unrevoked keyboxes are publicly available.