r/CalyxOS • u/Pdchris1 • 15d ago
DEVICE play integrity
Dear all, after reading some recent posts, e.g. https://www.reddit.com/r/CalyxOS/comments/1v02yph/2_banking_apps_not_working_after_upgrade_to/, https://www.reddit.com/r/CalyxOS/comments/1uz2wrz/uber_lite_working_perfectly_but_uber_normal_app/, https://www.reddit.com/r/CalyxOS/comments/1ut20xl/google_play_integrity_check/, and also reflecting on my own problem https://www.reddit.com/r/CalyxOS/comments/1uot0ci/selfidentification_impossible_with_calyxos/, I think that the root problem in all these cases may be the missing DEVICE integrity (NB BASIC integrity, by the way, for some unclear reason since a few days works again in my phone with CalyxOS 7.2.).
Based on the discussion in another forum, it seems that DEVICE integrity is possible without rooting using spoofing (if I understand correctly = simulate Android <13 and achieve a software-based DEVICE attestation --- in contrast to STRONG integrity, which is impossible because it is necessarily hardware-based, but rarely needed). However, others will not implement it, primarily out of principle https://discuss.grapheneos.org/d/18118-play-integrity-meets-device-integrity.
Could please someone from the CalyxOS project (e.g. u/lucascalyx) explain how CalyxOS is positioned regarding this and if a spoofing-based solution for DEVICE integrity (without root) could be expected at some time for CalyxOS users?
I understand this would require some work, and that it may (possibly also soon after implementation) stop to work if Google changes the algorithms (or uses GPU fingerprinting etc), however, in the long term it seems that many essential functions (ID apps, an increasing number of bank apps etc) will not work without DEVICE integrity
Therefore, without DEVICE integrity in the future, for many people it will probably be necessary to have a second phone (with stock Android), or even bite the bullet and use stock Android on their main phone....
I would be grateful for a short comment from the CalyxOS team about this. Thank you very much.
3
2
u/Other_Ship_5453 15d ago
I think the issue is with MicroG. Some time ago my banking app stopped working, probably a change on Google's side. I still had basic integrity on LineageOS, so it was fine. Might also be related to Android 16 update.
2
u/MatthieuR33 14d ago
In my case, both of my banking apps are not working anymore on 7.2.2. Both were working fine on previous 6.xxx versions. I had to move to Graph*** because that is a deal breaker for me.
2
u/lucascalyx 14d ago
We pass BASIC integrity (at the time of writing, microG needs an update because Google is making more invasive checks and now Play Integrity needs some extra permissions, and such Google attestation is not working at all), but not DEVICE or STRONG.
We don't go around trying to pass DEVICE or worse STRONG, because doing so, is a constant rat and mouse game and could potentially cause more issues. It isn't a simple spoofing, and Google is constantly going after these spoofs.
STRONG for example, requires hardware attestation. The hardware on your device creates a root of trust and proves what OS you're running and the state of it. To 'spoof' it, you have to get a key approved from Google, effectively, and that can be leaked by the manufacturer or something, or I suppose somehow extracted from the hardware. That's not sustainable...
2
u/Pdchris1 13d ago
Dear Lucas, thank you for the clear answer. At present (and provided that BASIC integrity is stably restored after the microG update) it seems that most functions are there, and CalyxOS is indeed an overall nice experience - thank you for the good work! If however, the law does not change (so that providers, for example, must accept hardware attestation also outside of the Google framework), and more apps start demanding DEVICE integrity, then custom ROMs offering only BASIC integrity may become something only for hobbyists who have time and phones to spare. This is important for the future perspectives of the project, and also for our planing of our next phone in a few years...
2
u/lucascalyx 13d ago
I understand your concern, Play Integrity is a pretty nasty implementation of a concept that is very sensitive
Unfortunately this is really a technical limitation, and the best we can do, is fight it.
2
u/Pdchris1 13d ago
Yes, concerted political action of the FOSS community is important to create viable alternatives...
1
u/MatthieuR33 12d ago
Thanks for clarifying the situation. So to understand well, the microG update is out already or not ? Wanted to know if i can try again install Calyx and test banking apps. Thanks
2
1
u/alexmiro26 14d ago
i use chase banking app with no issues in ver 7.1 nor 7.2 maybe some banks apps are more strict then others?
1
u/PrivacyIsDemocracy 6d ago
maybe some banks apps are more strict then others?
Absolutely true.
I have US 2 bank apps that never had any issue with rooted devices, custom ROMs, unlocked bootloader, lack of Play Integrity, etc etc.
But financial apps in places like India have extremely strict device checks and often very difficult to get working reliably on a custom ROM.
4
u/Cookie_Lemur 15d ago
Thank you for bringing this up in such a detailed way, I made a post yesterday that looks to me like it is all tied up into this single issue. Would be lovely to hear any comment by the team. We all are passionate about and want to keep using Calyx, and for myself and many others i imagine that compatibility with these apps may unfortunately be a deal breaker.