Live data from Hacker News

Viewing profile — AppAttestationz

AppAttestationz

HN member
Joined
Sun, Apr 05, 2026, 12:09 AM UTC
HN karma
9
Public activity
16 items

About AppAttestationz

No profile information was provided.

Recent public activity

  1. comment
    Comment #49192027

    1. A concern is not invalid merely because something else is worse. 2. Leaping to influence by foreign state is non sequitur. What evidence have you observed for that? How do I kno…

  2. comment
    Comment #49002214

    Truth be told, GrapheneOS is the only third party ROM that bothers to make app attestation work.

  3. comment
    Comment #48998736

    Wondering how webauthn extensions will fit into this. PRF for example, takes salts as inputs, if extensions are taken into consideration then it would need to capture input & clien…

  4. comment
    Comment #48794424

    [flagged]

  5. comment
    Comment #48091747

    With the amount of changes they've made to WebKit, I honestly don't think we can claim it's just JSC.. https://github.com/oven-sh/WebKit/commits/main/

  6. comment
    Comment #48091725

    I agree with Graphene's take here. I've defended app attestation against baseless criticism, but this is a valid take. The only nuance I would make is that hardware attestation as …

  7. comment
    Comment #48081633

    I suspect that the test suite isn't that great tho. Bun has so many different behaviors compared to other JS engines, sometimes just plain wrong or contradicting the spec. Test sui…

  8. comment
    Comment #48081627

    I suspect that the test suite isn't great. Bun has so many different behaviors compared to other JS engines, sometimes just plain wrong or contradicting the spec. Test suite didnt …

  9. comment
    Comment #48015503

    Notepad+++ was born.

  10. comment
    Comment #47647040

    It's a funny comment, because actual malware, very much loves to tamper with the bootloader and OS. Which was the motivation for cryptographically attesting the boot process and OS…

  11. comment
    Comment #47646609

    You can bicker about the words all day long. Legitimacy, or perhaps better: authenticity, in this context, would be a bootloader or OS that doesn't allow tampering with the executi…

  12. comment
    Comment #47645140

    Your whole point is orthogonal to what I said too. I said the title is misleading, which it is. Your argument that app attestation should be avoided because big tech company can wi…

  13. comment
    Comment #47645057

    I made an account because I'm qualified to talk about this topic :-) I've spent a considerable time testing every corner case of UX, and DX of an app attested service. App attestat…

  14. comment
    Comment #47644968

    I agree, there is still a reliance on the tech giants that produce the phones, who are the o'es embedding the cryptographic keys, to make this end to end attestation work. But in p…

  15. comment
    Comment #47644943

    I spent months designing a system, exactly like this. An account is not needed, at least for Apple. Play Integrity could the worst offender here, as it can be leveraged to force a …

  16. comment
    Comment #47644905

    The title is misleading. App attestation does not require an Apple account nor a google account. For Android, it does limit the ROMs to Google certified ones and requires GMS to be…