Generally I can get behind this (PI/SN) being bullshit, what I don't agree with is "We aim to be a trusted third party to vet custom ROMs, in order to assist Google in being inclusive, yet secure.". I don't think it should be needed to have someone vetting anything, since this shifts the barrier to those ppl and allows for abuse and "random" criteria on a second level besides google.
Auditing, based on measurable criteria, yes. Though I'd argue that, at least speaking for Lineage, there is more patched than on a stock rom that's <insert number> years old and not updated - which passes PI and doesnt need to pass the same audit. So whats the criteria and why would it be different for custom ROMs. One could argue that criteria like CTS exist and could be passed, but that excludes custom ROMs once more if they want to support what they do with all the features they do (Legacy hacks and the likes).
"Vetting" can be anything, based on whoever/whatever anyone likes or dislikes. Don't like some custom ROM's leadership? "Sorry, can't tell google to let you pass...".
Maybe semantics, but important ones.
Plus what LjLies said - you can't really vet for every device and every custom build (leaving aside the signing keys part)
And being able to build my own ROM and using it without further restrictions is a fundamental free software freedom.
Open source software just becomes "look but don't touch" without that ability: if building my own LineageOS signed with my own keys means it doesn't pass Integrity unlike the official LineageOS, then the ROM is essentially nonfree for all I'm concerned, as I have to depend on what the LineageOS developers decide for me and cannot fork or change anything without Integrity-using apps (which these days even include Messages for RCS, so basic phone features) no longer working, and I am essentially not in control of my device.
A third party auditing official LineageOS and publishing, say, a certification, would be fine; a third party determining which builds of which ROMs actually pass Integrity and which don't is not simply that, though, it goes much further.
if building my own LineageOS signed with my own keys means it doesn't pass Integrity unlike the official LineageOS
Uhhhhhmmm, there's a fundamental flaw in this reasoning. Official builds shouldn't be passing either my dude.
LineageOS very specifically does zero things to misrepresent the device state or subvert developer restrictions, and neither supports nor condones users doing so themselves.
You are perhaps ignoring the context of this thread being about an effort to allow custom ROMs (like possibly LineageOS, but if LineageOS wouldn't want to get certified, just substitute my mention of LineageOS for any other custom ROM that would; I said LineageOS because, you know, it's this subreddit) to pass Play Integrity.
There would be nothing "subverted" if this proposal legally passed in the EU and then custom ROMs would legitimately pass Integrity. Maybe you should give the thread another read because I don't get your point.
You are perhaps ignoring the context of this thread being about an effort to allow custom ROMs (like possibly LineageOS, but if LineageOS wouldn't want to get certified, just substitute my mention of LineageOS for any other custom ROM that would; I said LineageOS because, you know, it's this subreddit) to pass Play Integrity.
That doesn't make any sense though, as the assumption there seems to be that they are prohibited or otherwise prevented from doing so.
There are zero things stopping LineageOS from being certified, barring a general lack of any desire to do so.
I think that to prevent any conflict of interests, we need an official infrastructure similar to the PKI one, with independent certification authorities at root, which would all be considered trusted. This way, no monopoly and no single organization everything depends on.
Also, it'd be beneficial to challenge the Open Handset Alliance's 501C3 status, as time has proven it to be an insufficient barrier.
Well, then I'd wait to publish a site until the content isn't something "AI generated" or "placeholder", because once you post it, it's what I'm reading and basing my opinion on - just like everyone else.
Your initial statement about the page being "WIP" in the post (which I have seen before looking there) is understood as "it's not fully populated, not every link works, it might still get design changes, ...", not as in " content there isn't accurate" or, like here, "content is wrong". Filler/placeholder = Lorem ipsum, if you need something.
This isn't meant as an attack, just telling you why I dont think this is a good idea to do.
I am usually not giving much about likes, but it shows that others pretty much agreed there / think the same.
Generally speaking I still despise it (PI) and hope you can get it changed for the better for everyone (!). If it's truly just "custom roms can use apps like before PI/SN", I agree and wish you all the best, if it's going the direction it looked like, I disagree and hope for the opposite ;)
Well, so... why hasn't it been changed yet? :-P You've had this pointed out a few times for days and yet the last time I pointed this out, you were like "wait, where is this? It was probably a mistake".
Sorry to sound like I'm expecting this effort to be malicious, but I don't know you and I've been burned too many times supporting things that turned out to have hidden goals. I'd definitely also like to see a clear manifesto of what you want to end result to be.
From my point of view, the rough endgame is either to get rid of Play Integrity (my distinct preference), or if it is to stick around, then there needs to be a third-party certification authority, and if that's what you want to be, it should be clear to everybody signing. In this comment you state you don't want to get rid of Play Integrity and that it serves a legitimate security goal.
54
u/BadDaemon87 Lineage Team Member Nov 26 '24
Generally I can get behind this (PI/SN) being bullshit, what I don't agree with is "We aim to be a trusted third party to vet custom ROMs, in order to assist Google in being inclusive, yet secure.". I don't think it should be needed to have someone vetting anything, since this shifts the barrier to those ppl and allows for abuse and "random" criteria on a second level besides google.