Unified Attestation

There is nuance, as always. Not everyone uses GPI, as there are several “Integrity Check” and “App Security” frameworks on the market.
From my experience, only the “hardliners” like some payment apps and the entertainment industry tend to use it. You can also exclusively secure only parts of you app, for example a working banking app, but NFC payments cannot be set up without a passed integrity check.

As for why it’s used: Easy way to tick off a checkbox on the compliance requirement checklist for the developer. Minimal effort, industry standard protection. Therefore it’s really a good thing that an alternative is being developed. Let’s hope they get it right … and that Jolla includes it in SFOS/AAS.

Otherwise, there will just be one more integrity check system blocking SFOS devices from using certain apps. :smiley:

10 Likes