Live data from Hacker News

reCAPTCHA Mobile Verification Is Bringing the Play Integrity API to Desktops

discuss.grapheneos.org

71–74 of 74 posts

Re: reCAPTCHA Mobile Verification Is Bringing the Play Integrity API to Desktops

#71
post #66

Earlier quoted context omitted.

> Attestation isn't against being able to do whatever you want with your own device. “Prison isn’t against being able to go wherever you want.” > There are many changes that are possible which do not harm the integrity of applications. “Well there’s a lot of places you can go in prison, you just can’t leave.” Uh-huh. > In the same way the user can't make their device have the Microsoft Word app send them $1 million f…

>“Prison isn’t against being able to go wherever you want.” This isn't a good analogy since the user really able to do whatever they want with their computer. A better analogy is that. "You can go wherever you want, but if you are trespassing on other people's property they can report you to the police." Just because you have the freedom to go anywhere does not mean you are not accountable for your actions or that pe…

Distinguish between trespassing-style "you can go there but there might be consequences" and prison-style "you are physically unable to go there"

Currently it's trespassing-style. If you modify your Google client, Google reserves the right to ban you.

With attestation it's prison-style: you can't modify your Google client. If you try, the modified client just won't work. Trying to walk out of the prison wall does not actually put you outside - you just bang into the wall and then you are still inside.

Re: reCAPTCHA Mobile Verification Is Bringing the Play Integrity API to Desktops

#72

Earlier quoted context omitted.

Realistically, in which scenario this information can be useful? I can't think of anything, it should be removed. It's been misused by banking app and games, I've never seen a legitimate use case.

To verify that the user or someone who had physical access to the device (border checks, etc.) hasn't messed with the firmware. If I were a bank I wouldn't want to be on the hook for someone getting their bank account drained by the custom ROM someone downloaded from XDA. Then there's the DRM thing, where copyright owners make companies like Netflix sign a document like "if you don't enforce strong DRM, you cannot se…

If attestation didn't exist, media companies wouldn't require it.

Re: reCAPTCHA Mobile Verification Is Bringing the Play Integrity API to Desktops

#73

Earlier quoted context omitted.

> My opinion on this is that any method to check integrity, root access or if developer mode is enabled is a security vulnerability by itself, no such app should be able to know that. I think knowledge of such information should be available to all apps, but I think apps should not be so annoyingly restrictive. There's absolutely no reason why games or generic apps need to act on any of this information.

I advised my mother to do her banking on her phone instead of laptop. Hardware attestation kills privacy- yes. But it also works. Mobile phones are ridiculously locked down compared to legacy platforms such as Windows.

It's simply about segregation. If you have one device that is kept secure and another that is not, use the secure device for banking. Can be two phones, two PCs, or a phone and a PC.
Post reply on HN