Earlier quoted context omitted.
> important security measure It's a security measure against the owner of the device , in other words, an attack. Would you be okay with me using a remote control to forcibly slow down your car so I can merge? Using attestation this way is fundamentally incompatible with ownership. If the bank wants some assurance about a device, they need to sell or issue one to me, like credit cards or point of sale machines, which…
> If the bank wants some assurance about a device, they need to sell or issue one to me, like credit cards or point of sale machines, which are explicitly not your property. In this example, a banking app is not making the entire Android device non functional when it refuses to work when remote attestation like Play Integrity fails.
Like I said, I'd be fine if they offer a viable alternative, like a card or a physical authentication dongle (which doesn't require spyware to use).