Viewing profile — AppAttestationz
AppAttestationz
HN member- Joined
- Sun, Apr 05, 2026, 12:09 AM UTC
- HN karma
- 9
- Public activity
- 16 items
- HN profile
- View on Hacker News ↗
About AppAttestationz
No profile information was provided.
Recent public activity
-
comment
Comment #49192027
1. A concern is not invalid merely because something else is worse. 2. Leaping to influence by foreign state is non sequitur. What evidence have you observed for that? How do I kno…
-
comment
Comment #49002214
Truth be told, GrapheneOS is the only third party ROM that bothers to make app attestation work.
-
comment
Comment #48998736
Wondering how webauthn extensions will fit into this. PRF for example, takes salts as inputs, if extensions are taken into consideration then it would need to capture input & clien…
-
comment
Comment #48794424
[flagged]
-
comment
Comment #48091747
With the amount of changes they've made to WebKit, I honestly don't think we can claim it's just JSC.. https://github.com/oven-sh/WebKit/commits/main/
-
comment
Comment #48091725
I agree with Graphene's take here. I've defended app attestation against baseless criticism, but this is a valid take. The only nuance I would make is that hardware attestation as …
-
comment
Comment #48081633
I suspect that the test suite isn't that great tho. Bun has so many different behaviors compared to other JS engines, sometimes just plain wrong or contradicting the spec. Test sui…
-
comment
Comment #48081627
I suspect that the test suite isn't great. Bun has so many different behaviors compared to other JS engines, sometimes just plain wrong or contradicting the spec. Test suite didnt …
-
comment
Comment #48015503
Notepad+++ was born.
-
comment
Comment #47647040
It's a funny comment, because actual malware, very much loves to tamper with the bootloader and OS. Which was the motivation for cryptographically attesting the boot process and OS…
-
comment
Comment #47646609
You can bicker about the words all day long. Legitimacy, or perhaps better: authenticity, in this context, would be a bootloader or OS that doesn't allow tampering with the executi…
-
comment
Comment #47645140
Your whole point is orthogonal to what I said too. I said the title is misleading, which it is. Your argument that app attestation should be avoided because big tech company can wi…
-
comment
Comment #47645057
I made an account because I'm qualified to talk about this topic :-) I've spent a considerable time testing every corner case of UX, and DX of an app attested service. App attestat…
-
comment
Comment #47644968
I agree, there is still a reliance on the tech giants that produce the phones, who are the o'es embedding the cryptographic keys, to make this end to end attestation work. But in p…
-
comment
Comment #47644943
I spent months designing a system, exactly like this. An account is not needed, at least for Apple. Play Integrity could the worst offender here, as it can be leveraged to force a …
-
comment
Comment #47644905
The title is misleading. App attestation does not require an Apple account nor a google account. For Android, it does limit the ROMs to Google certified ones and requires GMS to be…