Dear LineageOS and other third party Android OS users (including waydroid),
Google wages a war against us using 3rd party apps as a proxy. They are pretending that Play Integrity API (previously SafetyNet) protects the user, and recommend it to app developers.
What can you do against this? Before trying anything to circumvent PlayIntegrityAPI/SafetyNet, start by opening a ticket (sending a mail, adding a comment on play store, whatever) to the app maker that your using, and tell them you use a more secure OS than the one provided by your manufacturer, and that their use of Play Integrity API reduces your personal security. If even 10% of 1.5M LineageOS users open tickets, that should be enough to actually get back to a manager of said app that will actually decide what to do with it.
As some small proofs that Play Integrity API IS NOT about security, but about enforcing Google/OEM monopoly on the device you own:
- Play Integrity API didn't care about permissive SELinux for a very long time (even though that's trivial and non privacy-invasive to test), I don't know whether it's still the case.
- https://twitter.com/MishaalRahman/status/1752734296400379957 Play Integrity API punishes you for using a custom kernel
- To this day, it is still trivial for an attacker to bypass Play Integrity API. It has became annoying for the community who would rather do useful stuff. A full-time attacker just need to spend their day scouting for approved firmwares and re-use them
- I can extract the "key attestation" certificate (""ultimate level"" of Play Integrity API) of a Google-made device (a quite recent device, it has been upgraded up to Android 13), because real security is hard, and this key is still valid. Of course most other OEMs are worse in that regard, so if it's doable for Google-made devices, imagine what an attacker can do to simply target the weakest OEM. (hint: they simply publish those certificates over the internet)
tl;dr they spent all their headcount on enforcing that the firmware the user is using is the google/oem one, and none on enforcing the security of the firmware.