ExploreTrendingAnalytics
Nostr Archives
ExploreTrendingAnalytics
GrapheneOS1d ago
Android's standard hardware API doesn't require delegating verification to a centralized service. One or more neutral organizations could exist certifying devices and operating systems without providing a centralized API. Those organizations could simply provide signed releases with the roots of trust, revoked keys and operating system key fingerprints. Apps could use multiple different certifying organizations. This is already something Android's hardware attestation API fully supports today.
💬 1 replies

Thread context

Root: 41f0dbc446c5…

Replying to: de8934c84fee…

Replies (1)

GrapheneOS1d ago
Volla, Murena and iodé are each a for-profit company selling devices. Each of them has failed to keep up with important security patches and protections. Each has marketed their products as providing a level of security they don't provide. It's very clear why these 3 companies want to be in charge of choosing which devices and operating systems people are allowed to use. They want to make sure their products are permitted and want to have an advantage over others to boost their profits.
0000 sats