logoalt Hacker News

izacustoday at 12:02 AM1 replyview on HN

You can of course create an independent attestation database at any time and mandate its use - verifying that the custom OS you use fits minimum security requirements for digital ID use.

We use that approach in several other industries.

But.... that requires work beyond just complaining.


Replies

matheusmoreiratoday at 1:18 AM

> You can of course create an independent attestation database at any time

Ah yes. They're totally going to trust my self-signed certificates. They're totally not going to restrict their trust set to the corporate owned and surveillance friendly Google and Apple devices.

Come on now.

> minimum security requirements for digital ID use

Also known as "the user has no control over the device".

Because users who have control can simply spoof this silly "digital ID" and there's nothing anyone can do about it.

> We use that approach in several other industries.

Your industries include the user of the device in their threat models. They want the device secured against the user. Absolutely unacceptable.

show 1 reply