At my core, I am a technology geek. I have spent over twenty years in legal technology and a decade in cyber security. I spend my days working out how my firm can get the most from modern tech, securely. I’ve often been asked if that’s a conflict, the mix of new technology and cyber security, but I don’t think so, I have always considered those two things intertwined. Good security enables good technology, they reinforce each other.
The thing that has me practically pulling what’s left of my hair out, is that logic completely breaks down the moment I pick up my phone.
Like all of us, my phone holds my banking apps, authentication tokens, personal messages, family photographs, health data, location history, and work email. My phone knows where I sleep, where I work, who I talk to, what I search for, what I buy. My phone is the single richest source of personal information about me that exists anywhere.
It is also, by design, a surveillance device. Research from Trinity College Dublin found that both Android and iOS devices phone home constantly, even when the user has explicitly opted out of diagnostics. An Android device sends Google approximately 1MB of data at startup and another 1MB every twelve hours when idle. iOS behaves similarly, sharing device identifiers with Apple on the same schedule. Pre-installed apps phone home whether you open them or not. Your phone shares its hardware serial number, SIM serial number, and handset phone number with the platform operator continuously. Google’s advertising revenue in 2025 was $294.7 billion. More than 70% of Alphabet’s revenue comes from advertising, which means from your data. Apple markets itself as the privacy alternative, but its own apps collect detailed behavioural data for its growing advertising business, and its anti-tracking features conveniently exempt Apple from the rules it imposes on everyone else. The phone is not a product you bought. It is an advertising platform you carry in your pocket.
That is the context for what happened when I tried to secure it.
I updated a banking app last month, and then it refused to open.
Not because my phone was compromised, and not because my account was flagged. No, the app detected two things it did not like. The first was my keyboard. I use FUTO Keyboard, a privacy-focused Android keyboard that operates entirely offline. It has no network permissions and so it cannot transmit what I type. The banking app flagged it as a security risk.
The keyboard my banking app considers safe is Google’s Gboard, which has full network access. It records your typing history locally, then runs nightly training sessions on your saved keystrokes and sends the results back to Google through a process called federated learning. Researchers have demonstrated that these training updates can be reversed to reconstruct the original keystrokes. An Android Police analysis found you cannot even turn off Gboard’s internet access. But Gboard passes the check, while FUTO, the keyboard that physically cannot exfiltrate your data, does not. The Citizen Lab found in 2024 that eight of nine major cloud-connected keyboards had vulnerabilities affecting up to a billion users. Those pass too.
The second thing the banking app objected to was Android Private Space, a feature built by Google and described in its own documentation as a way to create a secure, isolated environment for sensitive apps. The banking app detected Private Space and blocked that too. When I was testing a different phone, a previous banking app from a major UK bank refused to run entirely because the phone was running GrapheneOS, a hardened Android fork that is demonstrably more secure than stock Android.
To regain access to my own banking app, I had to remove the privacy keyboard and leave Private Space. I actually had to make my phone less secure to satisfy a security check.
Most banking apps verify device trustworthiness through the Google Play Integrity API. It checks whether a device is running a Google-certified version of Android with Google Mobile Services licensed. It does not check whether the device is actually secure.
A five-year-old phone running obsolete Android 11 with no security updates still passes, while a fully patched GrapheneOS device, running the latest patches on verified hardware fails. The GrapheneOS project has said this directly: the API “permits devices regardless of how many years behind they are on security patches.” The check is not measuring security posture. It is measuring whether your device is licensed by Google.
Android already has a better option for verifying device security. A separate verification system built into the hardware can check whether a phone is genuinely secure, regardless of which operating system it runs. It could verify GrapheneOS and banks could use it today. However, most do not, because Play Integrity is bundled, free, and requires no extra work to implement.
Banking apps are also granted explicit permission by Google to scan your installed applications. Google Play policy simultaneously considers the inventory of installed apps to be personal and sensitive information, and then grants financial apps broad visibility into it regardless. Research published in 2025 found banking apps listing hundreds of apps individually in their manifest files to detect what you have installed without even triggering the formal permission system. This is how a keyboard with no internet access gets flagged. The app finds something not on a vendor whitelist and blocks you. The whitelist maps to commercial distribution channels, not security outcomes.
I am not ignoring the strong counterargument to my rant.
At work, I helped design a standardised, locked-down environment. You cannot validate every possible configuration, so you restrict your corporate environment to the ones you have assessed and accepted. A bank could reasonably say it is doing the same thing with its customers. But I would say that this argument breaks at a specific point. In corporate cybersecurity we assess the threat model and implement proportionate controls. The Play Integrity API has not assessed anything. It is applying a binary check that equates “Google-licensed” with “secure.” A validated environment is one where someone has assessed the risk. A vendor-approved environment is one that meets Google’s commercial requirements. A compliance check designed to verify licensing has just been repurposed as a security control.
Google built Private Space and Play Integrity. One tells you to isolate your sensitive apps in a secure container, while the other penalises you for it. If the compliance layer were optimising for security, Private Space would be a positive signal. Instead it is treated as a deviation from the expected environment. The expected environment is not the most secure one, it is the standard one.
Bruce Schneier and John Kelsey published a paper in 2025 called Rational Astrologies and Security. A rational astrology is something people treat as though it works, for social or institutional reasons, even when there is little evidence that it does. Play Integrity is a rational astrology. The bank’s security team needs to demonstrate that device integrity checks are in place. Play Integrity is backed by Google and costs nothing to implement. Choosing it is defensible, whether or not it actually does anything useful to improve security.
The deeper problem goes beyond a bad compliance tool. The business model of every major OS vendor is structurally incompatible with genuine user security.
A truly secure device would minimise data collection and give users full control over what their OS does and who it talks to. Every one of those goals directly reduces the data available for advertising and AI training. Security and surveillance are architectural opposites, and every major OS vendor has chosen surveillance as their revenue model. This is not only a phone problem. Windows 11 now ships with an advertising ID, Start menu recommendations driven by your activity data, Copilot processing queries through cloud servers, and Recall, which can take periodic screenshots of everything you do, with protections that a security researcher bypassed within months of launch. Privacy guides routinely advise disabling fifteen or more separate tracking settings, and Microsoft has been known to quietly re-enable them after updates.
Amazon already sells Kindles at two price points, one with ads and one without, and nobody finds it confusing. The economics would work for phones and laptops too. The choice does not exist because offering it would make the current arrangement visible.
If this were only a problem for people running hardened operating systems, it would be a niche complaint. It is not.
The EU has mandated that all 27 member states must offer Digital Identity Wallets to citizens by the end of 2026. The reference Android implementation includes Play Integrity checks. Italy and France have already shipped wallet apps that refuse to run on GrapheneOS. Waag Futurelab, a Dutch research organisation, identified the structural problem in June 2026: by embedding commercial attestation in public infrastructure, European governments are making civic participation dependent on a private company’s licensing decisions.
The EU fined Google €890 million in July 2026 for violating the Digital Markets Act through anti-competitive Play Store practices. Waag’s analysis explicitly states that Play Integrity “clearly violates the Digital Markets Act.” The EU is simultaneously punishing Google for anti-competitive behaviour and building its own public identity infrastructure on their proprietary tools.
You cannot function in 2026 without a phone. Banking, identity, two-factor authentication, travel, healthcare. There are only two major mobile operating systems and both are controlled by companies whose revenue depends on harvesting your data. When compliance frameworks treat those ecosystems as the definition of “secure,” opting out of tracking means opting out of society.
I do not want a different phone or to opt out of modern technology. I am a technologist after all, and I want this technology. I just want to be able to use it without handing over everything about my life as the price of admission. And I want someone, a regulator, a competitor, or just enough angry customers, to force the choice into the open.
Right now, the people getting most annoyed by this system are the ones practising the best security. But when the same compliance check determines whether you can hold a government-issued digital identity, it is no longer just their problem. It is a question about who gets to decide what ‘secure’ means, and right now, the answer is the company selling your data.
I write about AI, cybersecurity, and technology every Friday. Subscribe to get it in your inbox.
Sources & Further Reading
GrapheneOS. (9 March 2026). Statement on Play Integrity API. X/Twitter.
GrapheneOS. (December 2024). Statement on Play Integrity as anti-security. Mastodon.
GrapheneOS. (May 2026). Statement on government mandating Play Integrity for digital payments and ID. X/Twitter.
GrapheneOS. Attestation Compatibility Guide. grapheneos.org/articles/attestation-compatibility-guide
FUTO Keyboard. Google Play listing. play.google.com/store/apps/details?id=org.futo.inputmethod.latin.playstore
FUTO Keyboard GitHub. Issue #773: HSBC UK Banking App Will Not Load Unless FUTO Keyboard is Disabled/Removed.
Android Open Source Project. (2026). Private Space documentation. source.android.com
Google Play Console. QUERY_ALL_PACKAGES permission policy. support.google.com/googleplay/android-developer/answer/10158779
Prashant. (April 2025). Banking apps bypassing QUERY_ALL_PACKAGES via manifest declarations. MediaNama.
Knockel, J. et al. (2024). The Not-So-Silent Type: Vulnerabilities Across Keyboard Apps. Citizen Lab, University of Toronto.
AI.type data breach. (2017). 31 million users’ personal data leaked. CBS News, ZDNet.
Leith, D. J. (2021). Mobile Handset Privacy: Measuring The Data iOS and Android Send to Apple And Google. Trinity College Dublin.
Android Police. (July 2026). Gboard is a privacy nightmare. androidpolice.com
Alphabet Inc. (2026). Form 10-K, FY2025. SEC Filing. Google advertising revenue: $294.69 billion.
Kelsey, J. and Schneier, B. (2025). Rational Astrologies and Security. Rossfest Festschrift.
Waag Futurelab. (22 June 2026). European digital ID wallets are a gift to Google and Apple. waag.org
European Commission. (23 July 2026). Google fined €890 million for Digital Markets Act violations.
Amazon. (2026). Kindle pricing: $149 with Special Offers, $169 without. amazon.com


