[1] https://grapheneos.org/faq#:~:text=Apps%20can%20detect%20tha...
[1] https://grapheneos.org/faq#:~:text=Apps%20can%20detect%20tha...
'you can still do X through Y, they are not removing it' is a popular and often the top reply on posts related to companies tightening their walled gardens. It gives an immediate solution to the problem but it doesn't address the core issue. I wish that wasn't the case.
The discussion might have been mostly theoretical before, but it sure isn't anymore...
0: https://developer.android.com/google/play/integrity/overview
It's a cat and mouse game that would require significant investment and could make things look more suspicious, better to focus on adoption so it becomes harder for companies to make stupid decisions like this. I've seen a banking apps that have expressly added support for GrapheneOS with their hardware attestation after customers mentioned it.
Even dedicated anti-detect browsers are constantly blocked and need patches. It's not something I would want GrapheneOS to focus on.
From https://grapheneos.org/articles/attestation-compatibility-gu...:
> GrapheneOS not only upholds the app security model but substantially reinforces it, so it cannot be justified with reasoning based on security, anti-fraud, etc.
If you're using any type of adblock in your browser, you're essentially spoofing countless systems just to have those ads not show up. But if I'm having my operating system tell an app that I'm not OS XYZ that's fraud?
Sibling comment says running this simple curl command would be illegal. Guess what? It is illegal.