ma kasi jan asli

← map

gov.uk one login on grapheneos

current status: gov.uk one login currently enforces the google play strong integrity check on android

timeline

The gov.uk One Login Android application currently enforces Google Play Integrity at the strong integrity level. This creates vendor lock-in such that the application can only be used on devices running an android operating system approved by Google. The Google Play Integrity API is based on the android hardware attestation API (https://developer.android.com/training/articles/security-key-attestation), however it enforces Google's monopoly over android-based mobile devices. The gov.uk One Login app should make use of this lower level API, and allow non-Google-approved operating systems such as GrapheneOS, which have significantly better security than many devices that pass the Play Integrity strong integrity check. GrapheneOS provide information on making use of this API on their website: https://grapheneos.org/articles/attestation-compatibility-guide, along with explanations of their security standards and information about trusting their signing keys. I hope that the government can switch to making use of this API, and avoid further extending the Google monopoly into restricting what devices we can use to access government services.