logoalt Hacker News

fenaeryesterday at 5:15 PM3 repliesview on HN

Unfortunately the answer here is to not abide by the law. If there is a reasonable way to bypass this (as the cat-and-mouse game always seems to continue), and there is reasonable expectation to not be caught, then I see no moral quandary with ignoring such a consumer-hostile rule.


Replies

ExpertAdvisor01yesterday at 5:55 PM

There won't be a reasonable way to bypass it as it requires a Google authenticated manufacturer to leak the keys or an TEE exploit.

All public key boxes are banned and Google regularly bans new ones . That endpoint contains the list of revoked keyboxes : https://android.googleapis.com/attestation/status

show 1 reply
alephnerdyesterday at 5:55 PM

> Unfortunately the answer here is to not abide by the law

You realize in Viet Nam this means getting a "friendly" visit by the MPS/BCA, and if you continue eventually getting branded as a troublemaker.

show 1 reply
TZubiriyesterday at 5:46 PM

I'm assuming you would do this out of a political reason, or as a very technical and privacy aware user.

But you are providing an alibi for malicious users who, for example, might try to brute force logins from unidentified devices.

That would be one reason aside from the law. You are essentially positioning yourself on the same side as intruders.

show 3 replies