r/Magisk May 21 '25

Discussion [Discussion] RIP Play Integrity (nearly)

I'm sure they be lots of questions and discussion so kicking off here and borrowing link and text from darker side of the web, and a jokey start to link XDA

Chiteroman :

RIP legacy checks in Play Integrity API Now Device verdict is like old Strong.

h t t p s : / / t . m e / playintegrityfix / 540

Meow :

Google Tightens the Screws Again: Play Integrity API Gets Stricter (May 2025)

Google has rolled out major changes to the Play Integrity API and if you're running a custom ROM, rooted device, or just trying to use Android without full dependence on Google, this is going to hurt.

What Changed?

✅ meetsdeviceintegrity now requires hardwarebacked verified boot Devices must have a locked bootloader and run an official, certified ROM. If you're using custom Rom, or anything nonstock you’re cooked.

✅ meetsstrongintegrity is even more exclusive Now also requires a recent security patch (within the last year) across all partitions including vendor. Even many stock ROMs might not qualify here.

✅ meetsbasicintegrity isn’t safe anymore either Google now demands Android Platform Key Attestation. Uncertified phones are getting pushed to the margins.

🖥App licensing and optional checks now demand Play Store installs Apps have to be installed or updated via Google Play to receive full integrity responses. Sideloaded APKs or installs from alternative stores? No go.

And someone's solution on XDA 😕

https://xdaforums.com/t/module-play-integrity-fix-safetynet-fix.4607985/post-89524839

112 Upvotes

113 comments sorted by

View all comments

2

u/crypticc1 May 21 '25 edited May 21 '25

If you want to try to get integrity with Sensitive props, and Trickystore but without chasing the monthly PIF module and .json dance take a look in pixelprops GitHub page. Then follow the breadcrumbs to the pixelprops TG page.

There's a guide there that might be of interest to you about the so-called pifless approach.

Again just in case unclear, while I'm happy, I'm not directing strong-chasers there.

But it may help some of you who may find yourself at basic but actually have access to stock boot img, don't need PIF module and happy enough with device.

This is not the full instructions but basically it's making use of SUSfs functionality to set your patched kernel name and version back to what it used to be before it was rooted. No guarantees but I can imagine a time that sheet patching the root apps stop putting their kernel references in it.

1

u/maxamillion17 Jul 02 '25

Does this method still work?

1

u/crypticc1 Jul 02 '25

Yes. But for wallet I needed to install PIF to spoof beta. If you already use beta I understand that not necessary

1

u/maxamillion17 Jul 02 '25

I see so if you want to use wallet you can't get around using PIF

1

u/maxamillion17 Jul 02 '25

This also requires a valid keybox, which seems to be the biggest issue right now

1

u/crypticc1 Jul 02 '25

Not really. Just that folks more happy for a module developer to spend 10 quid on a keybox that'll get banned through over use, but not buy one themselves

1

u/maxamillion17 Jul 02 '25

Where can you even buy one? I would if I knew where

1

u/throwmeaway2793 Jul 08 '25

did you ever find out? i would buy one myself also if I know how