Earlier quoted context omitted.
> Google's play protect prevents me from using some apps on my phone running graphene. My banking app is one of them. Well, your bank is the one choosing to prevent your from running it on GrapheneOS. That's my whole point again! We need to regulate that: it should be forbidden to ban alternative OSes! Now complaining about the fact that side-loading will require a ONE TIME, "annoying" procedure is not helping this A…
I'd be happy with either approach, frankly. I just think yours is slightly less realistic. > Well, your bank is the one choosing to prevent your from running it on GrapheneOS. That's my whole point again! We need to regulate that: it should be forbidden to ban alternative OSes! The bank isn't banning graphene os. They're banning anything Google labels as untrusted. I think that's an important distinction. This is Goo…
I don't agree here :-). AOSP provides an attestation mechanism that totally works with GrapheneOS [1]. Google provides Play Integrity on top of that, as an easy way to check that the phone is signed by Google. It doesn't say "it's unsafe if it is not signed by us", it just says "here is a way to verify that it is signed by us".
The bank chooses to check that it is signed by Google and to refuse everything that is not. The bank chooses that.
First, they don't need to check at all. Many banks don't, it seems like it's a new thing. I don't believe that there is any security concern there: it probably has to do with policy, or security theatre. It isn't serious security, because serious security would not ban GrapheneOS. I doubt it is to help Google, I think it's just incompetence (and a cheap way to do security theatre).
Most apps run on GrapheneOS, most apps don't use Play Integrity. Those who do choose to do it. And there are banks that choose to support the GrapheneOS attestation, though it's the exception.
[1]: https://grapheneos.org/articles/attestation-compatibility-gu...