Viewing profile — summm
summm
HN member- Joined
- Mon, Sep 18, 2017, 4:14 PM UTC
- HN karma
- 1,261
- Public activity
- 358 items
- HN profile
- View on Hacker News ↗
About summm
No profile information was provided.
Recent public activity
- story
- story
-
comment
Comment #48784248
Can you recommend some?
-
comment
Comment #48759058
I think Meneth was basically correct but a bit imprecise: Boot integrity itself is only user respectful as long as the user can freely decide and change the integrity reference val…
-
comment
Comment #48751069
So now you have the choice between two approved ROMs. Not a lot of improvement? And as soon as GrapheneOS implements something beneficial to the users that the government does not …
-
comment
Comment #48736654
No, this would just require a publicly verifyable signature of the software, and the user would just choose to have their operating system verify it. No remote attestation or other…
-
comment
Comment #48736454
Nope. It is still not possible to give someone else (the government, or the bank) control over your phone while at the same time run software that you alone control with higher pri…
-
comment
Comment #48577998
My opinion: Any kind of attestation that is delivered to a non-user-controlled server about the state of a user's end device that the user (possibly using means outside of the end …
-
comment
Comment #48576971
The GrapheneOS supporters are not on our sides, apparently. The seem to actually like remote attestation. They just don't like that they are not in on Play Integrity. But what is w…
- story
-
comment
Comment #48334292
Depends. In some sense EU companies are quite afraid of the GDPR. Privacy is used in a twisted way in that argument: if any privacy relevant data is exposed to another party, and t…
-
comment
Comment #48320734
They already add cryptographic authentication to some CAN messages, so you can't change them. It is only a matter of time until they add encryption. This is mostly a corporate prob…
-
comment
Comment #47935135
Only "open" in a twisted sense, and definitely not user-controlled: Remote attestation per definition means to accept only pre-approved operating systems. If anybody builds an impl…
-
comment
Comment #47850649
Their security model requires remote attestation. So, open, user-controlled platforms cannot be used. Of course some other future locked-down linux-based OS might be usable.
-
comment
Comment #47674782
Another "blog" that doesn't even offer an RSS or Atom feed...
-
comment
Comment #47382792
Yeah but many devices still do not support it, and if they support it, then badly, or they hide it. There is not even a USB-Bluetooth adapter that would enable LE Audio on Linux. (…
-
comment
Comment #47321480
In other news: "Unified Torment Nexus: open-source alternative to Google Torment Nexus" See also https://grapheneos.social/@GrapheneOS/116200110686604617
-
comment
Comment #47225250
Microwaves are a bad example. The cheaper ones are white labels basically all made in the same factory in China. The customer has no way to know if the slightly more expensive one …
-
comment
Comment #47215995
Motorola omitted a magnetometer in some of their models. This was especially heinous as the "compass needle" can be emulated to some degree by fusion if gps and rotation/accelerati…
-
comment
Comment #47215936
In fact Motorola did the opposite: they recently announced that in their opinion they found a loophole in the EU ecodesign regulation that they will exploit in order to not provide…
-
comment
Comment #47215909
Motorola, the one company that still tries to evade the EU ecodesign regulations? Other vendors just provide the required 5+ years of updates, but Motorola loudly and publicity ann…
-
comment
Comment #47131421
They actually already do in the EUDI wallet reference implementation. There, as this is part of a more general ID system, they probably want to avoid that people duplicate or expor…
-
comment
Comment #47131330
At least that establishes that you don't care about civil rights :|
-
comment
Comment #47131287
Nope, it is my system currently. I hope we won't go back to GDR where the government needed to approve eachtypewriter.
-
comment
Comment #47131210
You forgot to mention the additional remote attestation shackles you put on that trenchcoat. Note that I - as opposed to the posts parent - used an official trusted CA as an exampl…