Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. 🔐 Introducing: Unified AttestationAn open-source project for verifying the integrity of Android apps—as an alternative to Google's Play Integrity.

🔐 Introducing: Unified AttestationAn open-source project for verifying the integrity of Android apps—as an alternative to Google's Play Integrity.

Scheduled Pinned Locked Moved Uncategorized
vollavollaosopensourcesoftwarehardware
21 Posts 9 Posters 10 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • volla@mastodon.socialV This user is from outside of this forum
    volla@mastodon.socialV This user is from outside of this forum
    volla@mastodon.social
    wrote last edited by
    #1

    🔐 Introducing: Unified Attestation
    An open-source project for verifying the integrity of Android apps—as an alternative to Google's Play Integrity.

    The goal is to make apps such as banking and payment apps usable on independent Android systems without relying on Google services.

    We invite developers, ROM projects, and app providers to get involved.

    Link Preview Image
    Unified Attestation

    Unified Attestation is a free, open-source alternative to Google Play Integrity with offline verification and simple app + server integration.

    favicon

    (uattest.net)

    #Volla #VollaOS #OpenSource #software #hardware #Privacy #Security #DeGoogle

    lascapi@social.tchncs.deL torx@social.tchncs.deT j_r@social.jugendhacker.deJ lutindiscret@mastodon.libre-entreprise.comL downey@floss.socialD 5 Replies Last reply
    1
    0
    • volla@mastodon.socialV volla@mastodon.social

      🔐 Introducing: Unified Attestation
      An open-source project for verifying the integrity of Android apps—as an alternative to Google's Play Integrity.

      The goal is to make apps such as banking and payment apps usable on independent Android systems without relying on Google services.

      We invite developers, ROM projects, and app providers to get involved.

      Link Preview Image
      Unified Attestation

      Unified Attestation is a free, open-source alternative to Google Play Integrity with offline verification and simple app + server integration.

      favicon

      (uattest.net)

      #Volla #VollaOS #OpenSource #software #hardware #Privacy #Security #DeGoogle

      lascapi@social.tchncs.deL This user is from outside of this forum
      lascapi@social.tchncs.deL This user is from outside of this forum
      lascapi@social.tchncs.de
      wrote last edited by
      #2

      @volla looks very promising !! 👍

      grapheneos@grapheneos.socialG 2 Replies Last reply
      0
      • volla@mastodon.socialV volla@mastodon.social

        🔐 Introducing: Unified Attestation
        An open-source project for verifying the integrity of Android apps—as an alternative to Google's Play Integrity.

        The goal is to make apps such as banking and payment apps usable on independent Android systems without relying on Google services.

        We invite developers, ROM projects, and app providers to get involved.

        Link Preview Image
        Unified Attestation

        Unified Attestation is a free, open-source alternative to Google Play Integrity with offline verification and simple app + server integration.

        favicon

        (uattest.net)

        #Volla #VollaOS #OpenSource #software #hardware #Privacy #Security #DeGoogle

        torx@social.tchncs.deT This user is from outside of this forum
        torx@social.tchncs.deT This user is from outside of this forum
        torx@social.tchncs.de
        wrote last edited by
        #3

        @volla Interesting approach, but: How does #unifiedattestation ensure every interested other and secure alternative ROM can also pass the test?

        @GrapheneOS does heavily criticize your approach. They claim it puts you (your project) in charge of controlling which ROMs pass attestation and which do not.

        Is there any room for a collaboration? It sounds as if #GrapheneOS rules this out, how about you guys from @volla? Any negotiations possible? Any common ground?

        I, as a user, would just like to use those banking apps without worrying they might stop functioning anytime with any updates. Those banking-app-devs are the real culprits IMHO, to rely on something like Integritycheck theater.

        @volla is your secret that you will convince banking-app-devs to open up their checks?

        grapheneos@grapheneos.socialG 1 Reply Last reply
        0
        • volla@mastodon.socialV volla@mastodon.social

          🔐 Introducing: Unified Attestation
          An open-source project for verifying the integrity of Android apps—as an alternative to Google's Play Integrity.

          The goal is to make apps such as banking and payment apps usable on independent Android systems without relying on Google services.

          We invite developers, ROM projects, and app providers to get involved.

          Link Preview Image
          Unified Attestation

          Unified Attestation is a free, open-source alternative to Google Play Integrity with offline verification and simple app + server integration.

          favicon

          (uattest.net)

          #Volla #VollaOS #OpenSource #software #hardware #Privacy #Security #DeGoogle

          j_r@social.jugendhacker.deJ This user is from outside of this forum
          j_r@social.jugendhacker.deJ This user is from outside of this forum
          j_r@social.jugendhacker.de
          wrote last edited by
          #4

          @volla is opening up the attestation actually the way one should go? Attestation is harming the whole idea of FOSS because you can't run modified code on your own without significant drawbacks, so idk if it's the right way to build an "open" attestation process

          grapheneos@grapheneos.socialG 1 Reply Last reply
          0
          • volla@mastodon.socialV volla@mastodon.social

            🔐 Introducing: Unified Attestation
            An open-source project for verifying the integrity of Android apps—as an alternative to Google's Play Integrity.

            The goal is to make apps such as banking and payment apps usable on independent Android systems without relying on Google services.

            We invite developers, ROM projects, and app providers to get involved.

            Link Preview Image
            Unified Attestation

            Unified Attestation is a free, open-source alternative to Google Play Integrity with offline verification and simple app + server integration.

            favicon

            (uattest.net)

            #Volla #VollaOS #OpenSource #software #hardware #Privacy #Security #DeGoogle

            lutindiscret@mastodon.libre-entreprise.comL This user is from outside of this forum
            lutindiscret@mastodon.libre-entreprise.comL This user is from outside of this forum
            lutindiscret@mastodon.libre-entreprise.com
            wrote last edited by
            #5

            @volla thanks. Your approach is better than google having a monopoly on device attestation.

            grapheneos@grapheneos.socialG 1 Reply Last reply
            0
            • lascapi@social.tchncs.deL lascapi@social.tchncs.de

              @volla looks very promising !! 👍

              grapheneos@grapheneos.socialG This user is from outside of this forum
              grapheneos@grapheneos.socialG This user is from outside of this forum
              grapheneos@grapheneos.social
              wrote last edited by
              #6

              @lascapi @volla Android already has a hardware attestation system that's open to everyone unlike this centralized system. Volla, Murena and iodé are making a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

              GrapheneOS (@GrapheneOS@grapheneos.social)

              We strongly oppose the Unified Attestation initiative and call for app developers supporting privacy, security and freedom on mobile to avoid it. Companies selling phones should not be deciding which operating systems people are allowed to use for apps. https://uattest.net/

              favicon

              GrapheneOS Mastodon (grapheneos.social)

              1 Reply Last reply
              0
              • lutindiscret@mastodon.libre-entreprise.comL lutindiscret@mastodon.libre-entreprise.com

                @volla thanks. Your approach is better than google having a monopoly on device attestation.

                grapheneos@grapheneos.socialG This user is from outside of this forum
                grapheneos@grapheneos.socialG This user is from outside of this forum
                grapheneos@grapheneos.social
                wrote last edited by
                #7

                @lutindiscret Android already has a hardware attestation system that's open to everyone unlike this centralized system. Volla, Murena and iodé are making a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                GrapheneOS (@GrapheneOS@grapheneos.social)

                We strongly oppose the Unified Attestation initiative and call for app developers supporting privacy, security and freedom on mobile to avoid it. Companies selling phones should not be deciding which operating systems people are allowed to use for apps. https://uattest.net/

                favicon

                GrapheneOS Mastodon (grapheneos.social)

                1 Reply Last reply
                0
                • j_r@social.jugendhacker.deJ j_r@social.jugendhacker.de

                  @volla is opening up the attestation actually the way one should go? Attestation is harming the whole idea of FOSS because you can't run modified code on your own without significant drawbacks, so idk if it's the right way to build an "open" attestation process

                  grapheneos@grapheneos.socialG This user is from outside of this forum
                  grapheneos@grapheneos.socialG This user is from outside of this forum
                  grapheneos@grapheneos.social
                  wrote last edited by
                  #8

                  @j_r Android already has a hardware attestation system that's open to everyone unlike this centralized system. Volla, Murena and iodé are making a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                  GrapheneOS (@GrapheneOS@grapheneos.social)

                  We strongly oppose the Unified Attestation initiative and call for app developers supporting privacy, security and freedom on mobile to avoid it. Companies selling phones should not be deciding which operating systems people are allowed to use for apps. https://uattest.net/

                  favicon

                  GrapheneOS Mastodon (grapheneos.social)

                  1 Reply Last reply
                  0
                  • volla@mastodon.socialV volla@mastodon.social

                    🔐 Introducing: Unified Attestation
                    An open-source project for verifying the integrity of Android apps—as an alternative to Google's Play Integrity.

                    The goal is to make apps such as banking and payment apps usable on independent Android systems without relying on Google services.

                    We invite developers, ROM projects, and app providers to get involved.

                    Link Preview Image
                    Unified Attestation

                    Unified Attestation is a free, open-source alternative to Google Play Integrity with offline verification and simple app + server integration.

                    favicon

                    (uattest.net)

                    #Volla #VollaOS #OpenSource #software #hardware #Privacy #Security #DeGoogle

                    downey@floss.socialD This user is from outside of this forum
                    downey@floss.socialD This user is from outside of this forum
                    downey@floss.social
                    wrote last edited by
                    #9

                    @volla You're literally calling for centralization on the decentralized social network.

                    🤡

                    #Volla #VollaOS #OpenSource #software #hardware #Privacy #Security #DeGoogle

                    circus_maximus@social.anoxinon.deC 1 Reply Last reply
                    0
                    • R relay@relay.infosec.exchange shared this topic
                    • downey@floss.socialD downey@floss.social

                      @volla You're literally calling for centralization on the decentralized social network.

                      🤡

                      #Volla #VollaOS #OpenSource #software #hardware #Privacy #Security #DeGoogle

                      circus_maximus@social.anoxinon.deC This user is from outside of this forum
                      circus_maximus@social.anoxinon.deC This user is from outside of this forum
                      circus_maximus@social.anoxinon.de
                      wrote last edited by
                      #10

                      @downey @volla

                      It seems like a decentral phone home system - so your app as an app developer has its own "home server".

                      Not sure what the benefit of this is and the use case in general

                      downey@floss.socialD grapheneos@grapheneos.socialG 2 Replies Last reply
                      0
                      • circus_maximus@social.anoxinon.deC circus_maximus@social.anoxinon.de

                        @downey @volla

                        It seems like a decentral phone home system - so your app as an app developer has its own "home server".

                        Not sure what the benefit of this is and the use case in general

                        downey@floss.socialD This user is from outside of this forum
                        downey@floss.socialD This user is from outside of this forum
                        downey@floss.social
                        wrote last edited by
                        #11

                        @circus_maximus The last thing the world needs right now is another corporate gatekeeper promising "independence".

                        People have been fed that lie too many times to believe it anymore.

                        1 Reply Last reply
                        0
                        • circus_maximus@social.anoxinon.deC circus_maximus@social.anoxinon.de

                          @downey @volla

                          It seems like a decentral phone home system - so your app as an app developer has its own "home server".

                          Not sure what the benefit of this is and the use case in general

                          grapheneos@grapheneos.socialG This user is from outside of this forum
                          grapheneos@grapheneos.socialG This user is from outside of this forum
                          grapheneos@grapheneos.social
                          wrote last edited by
                          #12

                          @circus_maximus @downey @Torx Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                          GrapheneOS (@GrapheneOS@grapheneos.social)

                          Android provides a standard hardware attestation system with support for alternate operating systems via allowing their verified boot key fingerprints. It's mainly used with Google's root of trust and remote key provisioning service but the API supports alternative roots of trust. Volla's Unified Attestation is fully built on Android's hardware attestation API. It solely exists to create a centralized authority and service determining what's allowed under their control. https://mastodon.social/@volla/116238706890314617

                          favicon

                          GrapheneOS Mastodon (grapheneos.social)

                          1 Reply Last reply
                          0
                          • lascapi@social.tchncs.deL lascapi@social.tchncs.de

                            @volla looks very promising !! 👍

                            grapheneos@grapheneos.socialG This user is from outside of this forum
                            grapheneos@grapheneos.socialG This user is from outside of this forum
                            grapheneos@grapheneos.social
                            wrote last edited by
                            #13

                            @lascapi Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                            GrapheneOS (@GrapheneOS@grapheneos.social)

                            Android provides a standard hardware attestation system with support for alternate operating systems via allowing their verified boot key fingerprints. It's mainly used with Google's root of trust and remote key provisioning service but the API supports alternative roots of trust. Volla's Unified Attestation is fully built on Android's hardware attestation API. It solely exists to create a centralized authority and service determining what's allowed under their control. https://mastodon.social/@volla/116238706890314617

                            favicon

                            GrapheneOS Mastodon (grapheneos.social)

                            lascapi@social.tchncs.deL 1 Reply Last reply
                            0
                            • torx@social.tchncs.deT torx@social.tchncs.de

                              @volla Interesting approach, but: How does #unifiedattestation ensure every interested other and secure alternative ROM can also pass the test?

                              @GrapheneOS does heavily criticize your approach. They claim it puts you (your project) in charge of controlling which ROMs pass attestation and which do not.

                              Is there any room for a collaboration? It sounds as if #GrapheneOS rules this out, how about you guys from @volla? Any negotiations possible? Any common ground?

                              I, as a user, would just like to use those banking apps without worrying they might stop functioning anytime with any updates. Those banking-app-devs are the real culprits IMHO, to rely on something like Integritycheck theater.

                              @volla is your secret that you will convince banking-app-devs to open up their checks?

                              grapheneos@grapheneos.socialG This user is from outside of this forum
                              grapheneos@grapheneos.socialG This user is from outside of this forum
                              grapheneos@grapheneos.social
                              wrote last edited by
                              #14

                              @Torx Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                              GrapheneOS (@GrapheneOS@grapheneos.social)

                              Android provides a standard hardware attestation system with support for alternate operating systems via allowing their verified boot key fingerprints. It's mainly used with Google's root of trust and remote key provisioning service but the API supports alternative roots of trust. Volla's Unified Attestation is fully built on Android's hardware attestation API. It solely exists to create a centralized authority and service determining what's allowed under their control. https://mastodon.social/@volla/116238706890314617

                              favicon

                              GrapheneOS Mastodon (grapheneos.social)

                              grapheneos@grapheneos.socialG 1 Reply Last reply
                              0
                              • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                                @Torx Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                                GrapheneOS (@GrapheneOS@grapheneos.social)

                                Android provides a standard hardware attestation system with support for alternate operating systems via allowing their verified boot key fingerprints. It's mainly used with Google's root of trust and remote key provisioning service but the API supports alternative roots of trust. Volla's Unified Attestation is fully built on Android's hardware attestation API. It solely exists to create a centralized authority and service determining what's allowed under their control. https://mastodon.social/@volla/116238706890314617

                                favicon

                                GrapheneOS Mastodon (grapheneos.social)

                                grapheneos@grapheneos.socialG This user is from outside of this forum
                                grapheneos@grapheneos.socialG This user is from outside of this forum
                                grapheneos@grapheneos.social
                                wrote last edited by
                                #15

                                @Torx We're completely willing to file a lawsuit against @volla over this as soon as there are apps permitting their products through their system while disallowing GrapheneOS. It's not legal for Volla and multiple other companies to get together to implement a system banning using anything other than their products. We aren't going to participate is an illegal anti-competitive cartel. It's clearly against the law and should be stopped now prior to it causing clear damages to GrapheneOS.

                                grapheneos@grapheneos.socialG 1 Reply Last reply
                                0
                                • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                                  @Torx We're completely willing to file a lawsuit against @volla over this as soon as there are apps permitting their products through their system while disallowing GrapheneOS. It's not legal for Volla and multiple other companies to get together to implement a system banning using anything other than their products. We aren't going to participate is an illegal anti-competitive cartel. It's clearly against the law and should be stopped now prior to it causing clear damages to GrapheneOS.

                                  grapheneos@grapheneos.socialG This user is from outside of this forum
                                  grapheneos@grapheneos.socialG This user is from outside of this forum
                                  grapheneos@grapheneos.social
                                  wrote last edited by
                                  #16

                                  @Torx @volla Devices and operating systems providing an alternative to Google's ecosystem based on AOSP is a distinct space from the broader Android app ecosystem. Companies trying to give themselves an advantage through banning arbitrary options other than their own products/services is clearly an illegal anti-competitive tactic within that space. This should be halted before it causes harm to GrapheneOS. We will not tolerate apps permitting their products through it and banning GrapheneOS.

                                  grapheneos@grapheneos.socialG 1 Reply Last reply
                                  0
                                  • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                                    @Torx @volla Devices and operating systems providing an alternative to Google's ecosystem based on AOSP is a distinct space from the broader Android app ecosystem. Companies trying to give themselves an advantage through banning arbitrary options other than their own products/services is clearly an illegal anti-competitive tactic within that space. This should be halted before it causes harm to GrapheneOS. We will not tolerate apps permitting their products through it and banning GrapheneOS.

                                    grapheneos@grapheneos.socialG This user is from outside of this forum
                                    grapheneos@grapheneos.socialG This user is from outside of this forum
                                    grapheneos@grapheneos.social
                                    wrote last edited by
                                    #17

                                    @Torx @volla Volla and these other companies do not get to coerce us into participating in an illegal anti-competitive cartel where app compatibility would be harmed if we didn't participate. They do not get to coerce us into following their arbitrary demands and giving themselves veto power over GrapheneOS app compatibilities. Both Murena and iodé hostile towards GrapheneOS including spreading endless misinformation and direct involvement in spreading/supporting libel/harassment content.

                                    1 Reply Last reply
                                    0
                                    • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                                      @lascapi Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                                      GrapheneOS (@GrapheneOS@grapheneos.social)

                                      Android provides a standard hardware attestation system with support for alternate operating systems via allowing their verified boot key fingerprints. It's mainly used with Google's root of trust and remote key provisioning service but the API supports alternative roots of trust. Volla's Unified Attestation is fully built on Android's hardware attestation API. It solely exists to create a centralized authority and service determining what's allowed under their control. https://mastodon.social/@volla/116238706890314617

                                      favicon

                                      GrapheneOS Mastodon (grapheneos.social)

                                      lascapi@social.tchncs.deL This user is from outside of this forum
                                      lascapi@social.tchncs.deL This user is from outside of this forum
                                      lascapi@social.tchncs.de
                                      wrote last edited by
                                      #18

                                      Hi @GrapheneOS, you said :
                                      > Unified Attestation is anti-competitive and it clearly isn't legal.

                                      I don't get your point with this argument.

                                      If I understand well, Unified Attestation is a competitor of Google Play Integrity. And everyone can try to setup another competitor.

                                      How can you say that it's not legal?

                                      grapheneos@grapheneos.socialG xtreix@infosec.exchangeX 2 Replies Last reply
                                      0
                                      • lascapi@social.tchncs.deL lascapi@social.tchncs.de

                                        Hi @GrapheneOS, you said :
                                        > Unified Attestation is anti-competitive and it clearly isn't legal.

                                        I don't get your point with this argument.

                                        If I understand well, Unified Attestation is a competitor of Google Play Integrity. And everyone can try to setup another competitor.

                                        How can you say that it's not legal?

                                        grapheneos@grapheneos.socialG This user is from outside of this forum
                                        grapheneos@grapheneos.socialG This user is from outside of this forum
                                        grapheneos@grapheneos.social
                                        wrote last edited by
                                        #19

                                        @lascapi Multiple companies collaborating together to make a system which permits their products and forbids using alternatives isn't legal. The whole point of Unified Attestation is that it's a centralized system on top of Android hardware attestation putting these companies in control of which devices and operating systems are allowed. Companies making the products being certified should not be the ones deciding what's allowed. It's clearly not legal for them to be forbidding alternatives.

                                        grapheneos@grapheneos.socialG 1 Reply Last reply
                                        0
                                        • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                                          @lascapi Multiple companies collaborating together to make a system which permits their products and forbids using alternatives isn't legal. The whole point of Unified Attestation is that it's a centralized system on top of Android hardware attestation putting these companies in control of which devices and operating systems are allowed. Companies making the products being certified should not be the ones deciding what's allowed. It's clearly not legal for them to be forbidding alternatives.

                                          grapheneos@grapheneos.socialG This user is from outside of this forum
                                          grapheneos@grapheneos.socialG This user is from outside of this forum
                                          grapheneos@grapheneos.social
                                          wrote last edited by
                                          #20

                                          @lascapi They're pushing for banking and government apps to adopt a system which they control what's allowed to be used. They're going to be permitting their own products without reasonable security standards while locking out anything not participating in it. That's an anti-competitive cartel and not legal. We're not only going to heavily advocate against it but will file a lawsuit against Volla and the other companies involved as soon as there are apps using it while not permitting GrapheneOS.

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups