Google is tightening PI

I am not happy, who would’ve guessed?

So, who here uses rooted Android? Oh, right, literally just me, Cloudflare says I have basically no legit visitors. If you are a legit visitor, you’re definitely not the one-hundredth one — but since you’re already connected to the internet — might as well drop me some mail.

Back to what I was actually writing about, Play Integrity: For the unfamiliar, Google wants to make sure apps can know if a device is in an out-of-box state or actually usable. Tampered with, as Google likes to call it. The former option is the 255th layer of hell in most cases. The latter is what I’m using.

Google decided to bump the requirements for Android 13 and newer, as the integrity level for older, unmodified devices was easily attained with Magisk / APatch / KernelSU modules like Play Integrity Fix — PIF for short.

The new ones are pretty hard to get. I can’t even get the basic attestation anymore, which is rather annoying. Unrooting would be an option, but Magisk is just so useful

Have I mentioned Google uses proprietary byte code running in a quite secure environment for this? Huge props to people like chiteroman and osm0sis for dealing with this stuff. They may not make all of the world go round, but they sure do make mine.

I hope somebody finds a way to get just basic or device attestation again at some point. Until then, I’m using a keybox that will get revoked as soon as I look the wrong way — because some apps — especially the ones that don’t need it — really want integrity, whether I like it or not.

PS: First blog post where I asked an LLM to proofread. Hope you don’t mind. If you do, your problem.