Why they do this:
After the first three years, Volkswagen is charging ev customers €150/year to see the charge level on the app, remotely start the air conditioning, schedule charge and so on.
Any tinkerer is thinking "well, if I am paying this extortion just to see the charge level on the app, then I want to exfiltrate my data in home assistant or similar, getting better stats and so on"
So they blocked the API with Google play integrity signatures
Now, instead of spending money on engineering ways to block uncertified devices, they could have simply introduced an official API with rate limits and stuff.
The fact that they noticed all those "unauthorized accesses" it's prove that people just want to pay for a lightweight API access, not a 250mb app that takes 4 minutes to remotely start the air conditioning
After all, we're talking for €150/year for accessing the data of a €1 iot sim card using 0.0001€ of compute time. There should be enough margin for that.
