I don't understand Google's threat model for Android.
It assumes that it is more safe to either:
- Use stock outdated ROM
- Use custom rooted ROM with Magisk to hide tainted bootloader
- Use custom ROM with intentionally neutralized SafetyNet that always passes
Rather than using an updated custom ROM with self-signed locked bootloader that will actually trigger SafetyNet if malicious software will tamper with it.
Play Integrity API (SafetyNet's successor) has green status for fully verified, yellow for "you have a locked bootloader but you're on a custom ROM/self-signed", and orange-red for everything clearly bad. But the presence of the yellow state incentivizes developers to not trust anything below the green, and that's what happens in the real world.
Unless I'm missing something, I think it would be better if Google would get rid of the yellow status and considered self-signed to be green.
— cynical mode —
Or it's just a way to control the ecosystem and these decisions are in no way influenced by the security people but the management.
This is a repost of my old post that I need to reference regularly.
Post #23
185
- ❤ 3