Earlier quoted context omitted.
> It's funny that the EU uses all this mobile attestation BS more than the US does Attestation in on itself isn't unwarranted which (to me) is an important security measure. Attestation as commonly implemented on Android via Play Integrity (the way banking apps are known to do) is restrictive, sure: https://grapheneos.org/articles/attestation-compatibility-gu... / https://archive.is/snGEu
An important security measure for who, though? The servers at the bank should "never trust the client" in case the attestation is bypassed or compromised, which is always a risk at scale. If it's an important safety measure _for me_, shouldn't I get to decide whether I need it based on context? I think it's fair for banks to apply different risk scores based on the signals they have available (including attestation s…
Sure, banks could probably build a mechanism that lets some users opt out of this, just as they could add a Klingon localization to their apps. There just isn't enough demand.