gov.uk one login on grapheneos
current status: gov.uk one login currently enforces the google play strong integrity check on android
timeline
- 2026-08-17: issue #1005 was opened on the github repo for the android app, requesting grapheneos support
- 2026-08-31: i sent the following message to the gov.uk one login team:
The gov.uk One Login Android application currently enforces Google Play Integrity at the strong integrity level. This creates vendor lock-in such that the application can only be used on devices running an android operating system approved by Google. The Google Play Integrity API is based on the android hardware attestation API (https://developer.android.com/training/articles/security-key-attestation), however it enforces Google's monopoly over android-based mobile devices. The gov.uk One Login app should make use of this lower level API, and allow non-Google-approved operating systems such as GrapheneOS, which have significantly better security than many devices that pass the Play Integrity strong integrity check. GrapheneOS provide information on making use of this API on their website: https://grapheneos.org/articles/attestation-compatibility-guide, along with explanations of their security standards and information about trusting their signing keys. I hope that the government can switch to making use of this API, and avoid further extending the Google monopoly into restricting what devices we can use to access government services.