I've used LineageOS + MicroG on a pixel phone and it's been great being free of Google spyware.
I've used LineageOS + MicroG on a pixel phone and it's been great being free of Google spyware.
It's about as easy as it would be for an ISP to inject code into an HTTPS page.
The only reason anything works is because Google attestation servers still return a green light for evaluationType=BASIC. Once old devices become rare enough they'll only return a positive attestation for evaluationType=HARDWARE_BACKED.
Go find try and find a single instance of anyone achieving HARDWARE_BACKED with less than a fully stock device.
They are none. No amount of Magisk magic will make it work because it's all taken out of software's hands. Bypasses at that point look like electron microscopes and micro-electronics cleanrooms.
It tricks apps into thinking your phone doesn't support hardware key attestation, forcing it to fall back to basic software attestation which can easily be spoofed.
Been using it on my OnePlus 7 Pro and aside from when I had to switch to the fork, I haven't had any times where SafetyNet has stopped passing.