Conversation

I advocate to restrict hardware-backed SafetyNet evaluation to "real" security sensitive apps. Developers should go through an application process to qualify this level of API access. It is ridiculous for McDonalds to refuse to run on a bootloader unlocked device.
22
812
It works well and doesn't cause problems. Locking the bootloader to enable verified boot and attestation for alternate operating systems is fully supported by the specification. Pixel phones are among those implementing full support for alternate OSes. Most phones skip doing it.
1
6
There's nothing preventing an aftermarket operating system from fully supporting the modern A/B update system, the hardware-backed keystore, verified boot and other robustness/security features. Can do things at least as well as the stock OS. Nothing forces it to always be a toy.
1
1
Get app developers to care about their apps working on the many devices without Play Services and you won't have to deal with them having a hard dependency on SafetyNet. Alternatively, keep on that path and watch major apps stop being usable. They don't care about hobbyists.
1
7