Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

41–50 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#41

The thread is a bit vague. Am I understanding correctly that GrapheneOS Foundation's objection isn't to attestation per se, but that they can't participate in Google-controlled attestation APIs? In other words, although GrapheneOS can be cryptographically attested, apps using Google Play Integrity won’t accept it because it isn't Google-certified/GMS-licensed?

> Am I understanding correctly that [...] What I took away from the thread is that they're against services forcing attestation in general, and also pointing out that Play Integrity isn't about security, but rather about control, because Google could trivially make it work with GrapheneOS (which is more secure than any other Android OS on the market) but they won't.

> …Google could trivially make it work with GrapheneOS (which is more secure than any other Android OS on the market) but they won't.

But if Google did support third-party attestation, would the GrapheneOS Foundation be happy? Most of the thread seems to be a call for attestation to die, which feels impractical and unachievable. But "Google could use it to permit GrapheneOS for Play Integrity if that was actually about security" seems to be the real ask, and that seems reasonable and achievable. If that's true, I think it would’ve been more effective to lead with that and focus on it.

Re: Hardware Attestation as Monopoly Enabler

#42
post #2

This is a really good thread on why this technology is becoming a problem for "open" anything. The argument "we can create our own separate web" is fine until all of your services are behind the web that locks you into owning a Google approved or Apple approved mobile device.

Are there enough of us to run our own country? It makes me feel dumb, but this is a serious question.

[deleted]

Re: Hardware Attestation as Monopoly Enabler

#43
post #2

This is a really good thread on why this technology is becoming a problem for "open" anything. The argument "we can create our own separate web" is fine until all of your services are behind the web that locks you into owning a Google approved or Apple approved mobile device.

Are there enough of us to run our own country? It makes me feel dumb, but this is a serious question.

[deleted]

Re: Hardware Attestation as Monopoly Enabler

#45
These kind of things just make me want to use Graphene even more, or literally any platform that isnt the monopoly ones. Somehow I think AI and vibecoding, even if it may sound as an unpopular opinion, will allow people to build free ecosystems and actually usable devices that dont rely on the usual providers.

Re: Hardware Attestation as Monopoly Enabler

#46

Earlier quoted context omitted.

If you live in a democracy, you already do run your own country. Vote accordingly. Get involved in politics.

There are mountains of academic research showing that even in “democracies”, public opinion rarely translates into policy (by design).

The problem with that argument is that there really is no such thing as public opinion at scale. You can poll people/the general public on just about any issue and the answers are going to differ massively depending on framing effects. In the end, it's hardly better than just flipping a coin.

Re: Hardware Attestation as Monopoly Enabler

#48

The thread is a bit vague. Am I understanding correctly that GrapheneOS Foundation's objection isn't to attestation per se, but that they can't participate in Google-controlled attestation APIs? In other words, although GrapheneOS can be cryptographically attested, apps using Google Play Integrity won’t accept it because it isn't Google-certified/GMS-licensed?

My impression is that they are against remote attestation in apps/websites in general and if apps really want to do it, they should do it using the attestation API that AOSP already provides. The attestation API in AOSP allows companies to trust signing key fingerprints (such as those of GrapheneOS), which means that the attestation system is not controlled by a single company (Google).

The most damning part about Google Play Integrity is that, as the thread states, that Google lets devices pass that are full of known security holes, whereas they do not allow what is very likely to be the most secure mobile OS. This shows that they only use it as a method to shut out competitors and to control Android device manufacturers to pre-install Google software like Chrome (otherwise their devices do not get certified and won't pass Play Integrity).

IANAL, but anti-competition lawyers/bodies should have a field day with this, but nobody seems to care. Worse, the EU, despite their talk of sovereignty adds Play Integrity-based to their own age verification reference app.

I recommend every EU citizen, also if you do not use GrapheneOS, to file a DMA complaint about this anti-competitive behavior:

https://digital-markets-act.ec.europa.eu/contact-us-eu-citiz...

Also, every time this comes up, @ the relevant EU bodies, commissioners and your government's representative on Mastodon, etc.

Re: Hardware Attestation as Monopoly Enabler

#49
post #38
post #25

Earlier quoted context omitted.

FFS, cryptography is not the problem. How many times will we have to shut down that particular stupidity? Asymmetric cryptography is a corner stone of basically all online secure communications, and has been since before Google and apple were even founded as companies! (First invented in 1970) When did Https ever hurt you? That's built on asymmetric cryptography. Wherever you see the word "secure" it's basically shor…

Easy there I don’t want to take away your encrypted messaging. I’m just pointing out that the technology that enables it also enables the techno-totalitarianism we have been seeing rise since the mid 2010s

>Easy there I don’t want to take away your encrypted messaging

Then stop trying to take away the technology it's built on

Re: Hardware Attestation as Monopoly Enabler

#50

Earlier quoted context omitted.

> Am I understanding correctly that [...] What I took away from the thread is that they're against services forcing attestation in general, and also pointing out that Play Integrity isn't about security, but rather about control, because Google could trivially make it work with GrapheneOS (which is more secure than any other Android OS on the market) but they won't.

> …Google could trivially make it work with GrapheneOS (which is more secure than any other Android OS on the market) but they won't. But if Google did support third-party attestation, would the GrapheneOS Foundation be happy? Most of the thread seems to be a call for attestation to die, which feels impractical and unachievable. But "Google could use it to permit GrapheneOS for Play Integrity if that was actually abo…

Why should Google decide which devices are safe enough to pass remote attestation? Seems to me that if we want this at all, it should be an independent body that approves signing keys of vetted vendors (e.g. vendors roll out security updates timely, etc.).

As long as this is in Google's hands, they can abuse it to control the market.

That said, Play Integrity accepting GrapheneOS would be a step forward, but they will never do it, because then other vendors might also want to pass attestation without preloading Google apps.

Post reply on HN