RE: https://mastodon.social/@fsfe/116131145887510612
@volla has initiated the industry consortium #UnifiedAttestation for an open-source alternative to Google Play Integrity. That will be a game-changer. All major European OS producers are joining. We have a golden opportunity now to boot out Google.
@volla has initiated the industry consortium #UnifiedAttestation for an open-source alternative to Google Play Integrity. That will be a game-changer. All major European OS producers are joining. We have a golden opportunity now to boot out Google.

GrapheneOS
•https://grapheneos.social/@GrapheneOS/116239523775374959
GrapheneOS
2026-03-16 15:19:34
GrapheneOSudostępnił to.
Vollaficationist
•GrapheneOS
•GrapheneOS
•GrapheneOSudostępnił to.
HowToPhil (Phillip R)
•GrapheneOS
•Vollaficationist
•GrapheneOS
•GrapheneOS
•Aral Balkanudostępnił to.
GrapheneOS
•It would be better if root-based attestation didn't exist because it's fundamentally insecure for anything serious and primarily useful for anti-competitive and authoritarian purposes. Pinning-based attestation is what's useful for protecting users rather than controlling people.
Aral Balkanudostępnił to.
GrapheneOS
•2 użytkowników udostępniło to dalej
GrapheneOS i Aral Balkanudostępnił to.
GrapheneOS
•https://darknetdiaries.com/episode/146/
ANOM – Darknet Diaries
darknetdiaries.comGrapheneOSudostępnił to.
GrapheneOS
•GrapheneOSudostępnił to.
Vollaficationist
•GrapheneOS
•GrapheneOSudostępnił to.
Vollaficationist
•Dźwiedziu
•@GrapheneOS
Vollaficationist
•nelson abel - hombre vivo
•anon_4601
•I’ve read articles in Italian & Dutch outlets talking about the ‘danger’ of GrapheneOS, falsely claiming it's a phone for criminals. Some articles mentioned the new European Digital Wallet for storing IDs and payment cards; countries like Italy announced it wouldn't work on non-standard operating systems, only stock Android, iOS and GarminOS (all American companies). Some banks have lobbied against GrapheneOS and rushed to publish articles taking a similarly accusatory tone.
In fact, these are campaigns led by the far right. They are the same people pushing for age checks on all OSs in the U.S., the same Nazis who pushed in the EU for ‘Chat Control’—who, in the name of combating pedophilia, were prepared to launch a ‘Stasi 2.0’ rather than look at those Epstein files...
This just goes to show that I made the right choice in opting for GrapheneOS... the day I’m forced to use something else will be the last day I’ll ever own a phone.
GarretSidzaka
•If they did this, the entire Trojan Shield OP was just pre-work to ban GrapheneOS....not arrest criminals.
Vollaficationist
•GrapheneOS
•GrapheneOSudostępnił to.
Guillaume
•GrapheneOS
•GrapheneOSudostępnił to.
Vollaficationist
•GrapheneOS
•Vollaficationist
•GrapheneOS
•Chuckles
•Vollaficationist
•GrapheneOS
•GrapheneOSudostępnił to.
Vollaficationist
•GrapheneOS
•GrapheneOSudostępnił to.
Vollaficationist
•Vollaficationist
•Daniël
•Back to to the original topic. I only have a stake in this as an EU citizen, but having a small set of companies decide who can run what is bad, it's another attack on the freedom of EU citizens.
Karsten
•I would agree to the lower paragraph and add the following thought:
Maybe it would be wise to not let the only companies with privacy in the mind get divided. Arguments ad hominem are not very convincing.
@vollaficationist @celeduc @GrapheneOS @guilg @EUCommission @GrapheneOS
Daniël
•AFAIK the support for remote attestation that is already provided in AOSP does not suffer from this issue, because there is not a single entity that enforces it (banks can whitelist signing key fingerprints).
So the only reason I can think of is control.
Daniël
•Some European countries border on autocracy. Imagine that this initiative is successful. An autocrat could pressure Volla et al. to only attest phones that have a chat backdoor under the thread of banning them from the market.
It is anti-privacy, anti-security, and anti-freedom.
Karsten
•But that has nothing to do, whatsoever, with the attestation. That said state could pressure volla et al that only phones with backdoor are allowed in the EU.
@vollaficationist @celeduc @GrapheneOS @guilg @EUCommission
GrapheneOS
•GrapheneOSudostępnił to.
GrapheneOS
•Karsten
•But they, the EU, can do this all along. No matter if there is something like attestation or not.
@danieldk @vollaficationist @celeduc @guilg @EUCommission
GrapheneOS
•GrapheneOS
•GrapheneOS
•Karsten
•I guess I don't know enough about THW difference. So you have a link to an explanation?
@danieldk @vollaficationist @celeduc @guilg @EUCommission
Karsten
•That's true but essentially they could forbid it, even with higher impact and less success
@danieldk @vollaficationist @celeduc @guilg @EUCommission
Vlad_3301
•То денег на таки суды бы им не хватило. 🤣
Vollaficationist
•Vollaficationist
•Vollaficationist
•As for Canada law, would it be possible (legal) for you to get certificated by UA (without actively partaking in the consortium)?
GrapheneOS
•GrapheneOS
•Xtreix
•https://competition-policy.ec.europa.eu/antitrust-and-cartels_en
Unified Attestation is an initiative with Murena, Iodé, and Volla, three untrustworthy for-profit companies that want to copy Google Play Integrity API, which is already abusive and illegal, to manipulate the market and impose their misleading standards.
There is nothing neutral about it, and the fact that it’s “open-source” doesn’t change a thing.
Antitrust and Cartels
Competition Policymeowki
•The issue is that banks are required to have this attestation by credit card companies.
Xtreix
•The attestation compatibility guide is a good, neutral approach that is not controlled by a centralized authority : https://grapheneos.org/articles/attestation-compatibility-guide
Unified Attestation threatens the compatibility of apps for developers who refuse to participate in their illegal cartels. This seriously undermines the efforts of a project like GrapheneOS, which strives to make as many Android apps as possible compatible with a truly secure and privacy-respecting operating system, one without user accounts, AI, age verification, client-side analysis, or any default Google services nor any other tech companies, etc
We need to support it because there’s no one else doing what GrapheneOS does.
Banking Applications Compatibility with GrapheneOS
akc3n, Tommy, spring-onion (PrivSec - A practical approach to Privacy and Security)meowki
•Xtreix
•This is a significant difference compared to stock Android, where Google Play Services runs as a system app with elevated privileges that you cannot control. MicroG works in the same way and is often mistakenly presented as a more private alternative to Google Play Services.
What cross-app sandboxing doesn't protect is communication between apps based on mutual consent. If you install Instagram and Facebook on the same profile, the apps still only have access to what you authorize them to access, but since they belong to Meta, they could exchange telemetry data with each other.
To stop this, the solution is to use a system-wide secondary profile, which offers excellent isolation but is somewhat cumbersome to use, or the private space, which provides less robust isolation but is easier to use. This decision really depends on your threat model and whether or not you consider plausible communication between these applications to be acceptable.
https://grapheneos.org/usage#sandboxed-google-play
GrapheneOS usage guide
GrapheneOSmeowki
•Unified Attestation
Sailfish OS ForumXtreix
•Curve Pay work well on GrapheneOS for the contactless payment, available for EU users currently, and I recently discovered a interesting a project that look interesting, which is actually in development.
"Are there other alternatives to UA there?"
Unified Attestation is an alternative of Google Play Integrity API, both are abusive, illegal and completely useless.
The AOSP attestation hardware is available since Android 8, is functional, and is neutral.
https://github.com/eu-digital-identity-wallet/eudi-app-android-wallet-ui/issues/287#issuecomment-4085348754
https://www.curve.com/
https://walt.is/
https://techcrunch.com/2016/11/29/jollas-sailfish-os-now-certified-as-russias-first-android-alternative/
https://en.wikipedia.org/wiki/Aurora_OS_(Russian_Open_mobile_platform)
meowki
•It’s obvious to me that GOS is not really about de-googling, but rather to harden the security of Android.
Curve requires google play services. If that is where the GOS is comfortable it’s not an issue to me. However, we still need alternatives w/o GP.
Where I find it a bit discomfortable is the constant accusations that others are scammers/lying.
https://forum.sailfishos.org/t/plea-for-official-statement-from-jolla/10430/40
Do you have recent proof they are collaborating with Russia?
Anything you would like to add to this @jolla ?
Plea for official statement from Jolla
Sailfish OS ForumGrapheneOS
•> It’s obvious to me that GOS is not really about de-googling, but rather to harden the security of Android.
GrapheneOS is a privacy project. It's focused on privacy above everything else. Privacy depends on security.
You're presenting posts from an account which doesn't belong to GrapheneOS or any of our team members as if it's from us...
> Where I find it a bit discomfortable is the constant accusations that others are scammers/lying.
They should stop doing it.
GrapheneOS
•Privacy does not mean specifically avoiding Google services while using more privacy invasive services. Your reasoning for why Curve isn't a private option is extremely wrong. It's not the reliance on Google Play services which makes it bad for privacy.
You're presenting statements from an account not belonging to GrapheneOS or any of our team members as from us...
GrapheneOS
•GrapheneOS
•GrapheneOS
•Didek
•May be open to collaboration, but the thing is you still need collaboration with them. You cannot implement some protocol and have a software working, you need their special approval that the software you run is something they agree with.
Attestation is worse than DRM, it is very harmful no matter if coming from US or EU.
GrapheneOS
•GrapheneOSudostępnił to.
Vollaficationist
•GrapheneOS
•Vollaficationist
•GrapheneOS
•Vollaficationist
•Whatever, UA is open to anyone. And this fact is why the GOS dude is alleging, empty handed, that is illegal in Canada and EU. According to him/her it's probably globally illegal to contest googlag, right. You're welcome.
GrapheneOS
•> Doesn’t that seem a bit farfetched?
Nothing about it is farfetched.
> You don’t want to support it, fine.
No, we don't want these companies further degrading app compatibility with arbitrary options including GrapheneOS which is what their system is going to do.
> You rather trust the whims of Google than these companies, fine.
This is an outrageous misrepresentation of our position. We've been actively fighting and succeeding against the Play Integrity API for years now.
GrapheneOS
•> The fact is Google could also go out to of their way to require a version of this that will block these apps from running on your OS.
Play Integrity API is clearly illegal and substantial progress was being made to dealing with it. Having another anti-competitive system banning using arbitrary hardware and software based in Europe will help to legitimize and spread attestation to more apps.
> Perhaps it’s time to bury the axe?
Volla is welcome to discontinue Unified Attestation.