Pay securely with an Android smartphone, completely without Google services: This is the plan being developed by the newly founded industry consortium led by the German Volla Systeme GmbH. It is an open-source alternative to Google Play Integrity. This proprietary interface decides on Android smartphones with Google Play services whether banking, government, or wallet apps are allowed to run on a smartphone.

  • 20dogs@feddit.uk
    link
    fedilink
    English
    arrow-up
    6
    ·
    11 hours ago

    One or more neutral organizations could exist certifying devices and operating systems without providing a centralized API. Those organizations could simply provide signed releases with the roots of trust, revoked keys and operating system key fingerprints. Apps could use multiple different certifying organizations. This is already something Android’s hardware attestation API fully supports today.

    Then why doesn’t GrapheneOS offer that alternative to banks etc

    • potustheplant@feddit.nl
      link
      fedilink
      arrow-up
      1
      ·
      2 hours ago

      Because you can’t unilaterally just save credit card information and use it for payments. Your bank has to support and approve the app/service.