Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A person from Singapore here. In practice, this changes nothing (from the news standpoint). The most critical applications are already integrated with Play Integrity API. Singpass (ID system) is 100% unavoidable for every long-term visitor and has strict Play Integrity integration (but attacker can select SMS flow and nullify the protection). Banks and all financial organizations require Singpass too, also use Play Integrity in most cases. The biggest bank DBS has extra checks, like "if there is an .apk in Downloads directory, then device is considered as compromised" (and they recently disabled SMS bypass). The most funny case that a similar protection is used in McDonald's app (again, maybe enforced only in specific countries): have something sus on your phone -- no burgers for you! They also have extra checks (i. e. device passes "strong integrity test", but app refuses to work).

Another note: this obviously does not prevent people from having multiple phones, feel free to buy an extra phone and install LineageOS/Gentoo/whatever you want.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: