microg / microg/GmsCore

Safetynet turndown, Safetynet attestion test errors

Open
#3,034 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
Java
Stars
14.6k
Forks
3.2k
Avg merge
12d 11h
Merged PRs (30d)
4

Description

Describe the bug
Google announced long ago that Safetynet will be shutdown and replaced with PlayIntegrity, it appears that the servers that formerly responded to SN queries are now completely offline.

To Reproduce
Steps to reproduce the behavior:

  1. Open the microG utility app
  2. Go to the page under "Google Services" called "Google Safetynet"
  3. Make sure "Allow device attestation" is enabled
  4. Tap "Test SafetyNet Attestation"
  5. Note errors returned, test fails with error code 429, "quota exceeded", and "queries exceeded" errors.

Expected behavior
Historically: a result is returned without basic network errors.
Currently: At this point since Safetynet is now officially shutdown (not just deprecated), it seems that this function is now not only worthless but also confusing for users.

https://firebase.google.com/docs/app-check/android/safetynet-provider
https://developer.android.com/privacy-and-security/safetynet/deprecation-timeline

System
Android Version: 10,11,15 (tested on multiple devices)
Custom ROM: LineageOS official, CarbonROM, CalyxOS

Additional context
I note that the last version of microG included with CalyxOS (their own private build 0.3.7.250932-18 (b12b324)), does not even include a section under its "Google Safetynet" section to test either Safetynet attestation or ReCaptcha.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in the microG utility app's Google Services section, specifically the Google SafetyNet page and its attestation test, and review the linked SafetyNet deprecation documentation. Confirm how the unavailable service is currently surfaced; done should mean the obsolete test no longer produces confusing failures or is clearly handled for users.

Written by the indexing model from the issue text.

Assessment

Tech stack
android, java
Domain
mobile, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.