logoalt Hacker News

microtonaltoday at 12:50 PM1 replyview on HN

IMO the most annoying thing is that Google could solve this problem today by just adding the GrapheneOS signing keys to the whitelisted keys. Instead they decide to exclude GrapheneOS because security, while attesting phones that are still on Android 13 (multiple years without fixes for vulnerabilities that are not marked high/critical) and did not apply ASB patches for up to 12 months.

A first step would be requiring Google to attest all devices that have a locked bootloader, verified boot, signed with non-public keys, and have a recent Android version and patch level.

IMO they should also boot anything older than Android 16 and behind more than 1-2 ASBs, if security is the real reason to have Play Integrity remote attestation.


Replies

inigyoutoday at 12:58 PM

POSIWID: the purpose of remote attestation is to force people to buy devices that pay Google license fees.

show 1 reply