logoalt Hacker News

zb3yesterday at 11:40 PM1 replyview on HN

Note that Google also forces this indirectly via their "certification" - if the device doesn't have unremovable AVB (requires qualcomm secure boot fuse to be blown) then it's not even allowed to say the device runs Android.. if you see "Android™" then it means secure boot is set up and you don't have the keys, you can't set up your own, so you don't really own the SoC you paid for..


Replies

subscribedtoday at 2:38 AM

I don't think it's accurate.

Specifically GrapheneOS on Pixels signs their releases with their own keys. And with the rollback protection without blowing out any fuses.

show 1 reply