Earlier quoted context omitted.
[flagged]
Every Android system support remote attestation. It's part of AOSP. Google just decided not to use it, because Play Integrity allows them to lock in phone manufacturers and force them (per leaked agreements) to preinstall a bunch of Google apps and require to run Play Services and some other components privileged on the system.
European digital ID wallets rely on safety services of Google and Apple
251–260 of 327 posts
Re: European digital ID wallets rely on safety services of Google and Apple
#252Earlier quoted context omitted.
Exactly, I'm not sure what benefits hardware attestation offers to the government. Sure, it's potentially useful for the customer that they can trust their keys are secure on their device, but it kind of misses the point. It should really be an open-source specification that defines a standard protocol, but where the device just signs a request that it knows has come from a trusted source (so maybe signed by the gove…
I think the reason these systems require device bound keys is because the government is concerned with easily mass-produced forged age certificates. With software keys you can get an age certificate which can be copied instantly to a large number of devices, with hardware keys the government knows that the certificate is tied to a single physical unit.
Re: European digital ID wallets rely on safety services of Google and Apple
#253Earlier quoted context omitted.
And they already did that. The chief prosecutor of the International Criminal Court in The Hague was cut off Office 365 (and e-mail hosted through that), as well as credit cards and bank cards. This did send a shockwave through Europe.
To be fair, the ICC should not have existed in the first place. It was created to persecute the Serbs and then other people that were not liked by Europe mostly.
Trump made that whole arrangement cracking a little bit, but I still think it's mostly just the optics of it all they are still loyal servants. Nobody in Europe that matters gives a shit about Karim Khan or Francesca Albanese getting debanked and sanctioned, they would and love to do it themselves.
Re: European digital ID wallets rely on safety services of Google and Apple
#254Earlier quoted context omitted.
How can you have a secure enclave without hardware attestation? Processor root-key is the source for all.
Smartcards have attestation too.
Re: European digital ID wallets rely on safety services of Google and Apple
#255Earlier quoted context omitted.
As outlined here: https://grapheneos.org/articles/attestation-compatibility-gu... , GrapheneOS isn't implementing something unique, it's implementing Android Hardware Attestation: https://developer.android.com/privacy-and-security/security-...
Android Key Attestation produces attestations that are signed with a certificate chain rooted in the hardware vendor's CA. If you use Key Attestation on GrapheneOS on a Pixel device for example, it attests that you're using GrapheneOS's AVB keys, but that attestation is still signed by a Google certificate chain. "Adding support for GrapheneOS" means allowlisting their AVB keys specifically, it does not open a door f…
Re: European digital ID wallets rely on safety services of Google and Apple
#256The EU reference for wallets strictly required google play services https://github.com/eu-digital-identity-wallet/eudi-app-andro... So Italy's IO app https://github.com/pagopa/io-app (wallet, documents, age verification) continuously refuses the users' request for GrapheneOS support and requires google. Nothing will change until the lawsuits start coming in. The only hope is the motorola/grapheneOS collaboration and…
The issue isn't just the technical dependency. It's also the fact that it forces each citizen to pay a few hundred Euros to companies which then campaign against their very rights. Citizens get no support of any kind in case of issues, and has to enter a contractual agreement which is ridiculously asymmetrical, where the company has little to no responsibility of any kind, but has very ample rights to track the other…
Re: European digital ID wallets rely on safety services of Google and Apple
#257Earlier quoted context omitted.
Why is attestation always bad, all the time? When two people interact there’s a trust/risk calculation on both sides. Isn’t attestation just a means of reducing risk for both parties? (We can debate who should control the attestation process and how it should work but your point 1 suggests that there is never a good form of attestation.) What would we do instead?
I cannot think of any company that has appropriately used attestation as a trust/risk calculation. I work in major game studio; there is never calculation only a binary. It never „let`s check if the mobile user has purchased in-game content server side to prevent pirating it“, its „suspend any account that has signed in with a device that fails safetynet, permanently ban any account that has failed a jailbreak or roo…
Re: European digital ID wallets rely on safety services of Google and Apple
#258Earlier quoted context omitted.
posters upthread are talking about comprehension and value systems, not literacy. "functionally illiterate" is the brush that one paints with when describing people of opposing political viewpoint or lower socioeconomic status, for example.
I must be illiterate because this doesn’t make any sense to me Being kinda dumb and graduating school without reading a book is not a socioeconomic status
Re: European digital ID wallets rely on safety services of Google and Apple
#259The EU reference for wallets strictly required google play services https://github.com/eu-digital-identity-wallet/eudi-app-andro... So Italy's IO app https://github.com/pagopa/io-app (wallet, documents, age verification) continuously refuses the users' request for GrapheneOS support and requires google. Nothing will change until the lawsuits start coming in. The only hope is the motorola/grapheneOS collaboration and…
[flagged]
Re: European digital ID wallets rely on safety services of Google and Apple
#260Earlier quoted context omitted.
Why is attestation always bad, all the time? When two people interact there’s a trust/risk calculation on both sides. Isn’t attestation just a means of reducing risk for both parties? (We can debate who should control the attestation process and how it should work but your point 1 suggests that there is never a good form of attestation.) What would we do instead?
I cannot think of any company that has appropriately used attestation as a trust/risk calculation. I work in major game studio; there is never calculation only a binary. It never „let`s check if the mobile user has purchased in-game content server side to prevent pirating it“, its „suspend any account that has signed in with a device that fails safetynet, permanently ban any account that has failed a jailbreak or roo…
Nice