Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

rainer@johnmastodon.euR

rainer@johnmastodon.eu

@rainer@johnmastodon.eu
About
Posts
3
Topics
0
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • Doesn't work without a Google/Apple-tied device btw.
    rainer@johnmastodon.euR rainer@johnmastodon.eu

    @TimothyRoes @soulsource @khleedril @K4mpfie @ErikJonker @pojntfx
    Apparently, the standard Android hardware attestation API can attest more than just the hardware. From https://grapheneos.org/articles/attestation-compatibility-guide:

    "The standard hardware attestation API can be used to verify the authenticity/integrity of the hardware, firmware, OS and the app running on it. It provides a verified boot key fingerprint for the OS for permitting secure aftermarket operating systems. The app ID, signing key fingerprint(s) and version code of the app enabling hardware attestation are included in the signed public key certificate for the generated key. This enables the app's service to make sure the app is genuine and unmodified along with chaining trust through the OS to the app which can sign messages with the attested hardware keystore key to prove they come from their app running on top of a verified OS, firmware and hardware. The only practical way to bypass hardware attestation is through exploiting the hardware keystore to obtain attestation signing keys, which is protected against by the ability to revoke keys that are being misused. "

    Uncategorized

  • Doesn't work without a Google/Apple-tied device btw.
    rainer@johnmastodon.euR rainer@johnmastodon.eu

    @soulsource @TimothyRoes @khleedril @K4mpfie @ErikJonker @pojntfx

    This hardware attestation is Android-specific, but at least not tied to Google. That fixes a major problem for a major platform. One still needs a solution for serving the rest of the market in a similarly acceptable way, of course.

    Uncategorized

  • Doesn't work without a Google/Apple-tied device btw.
    rainer@johnmastodon.euR rainer@johnmastodon.eu

    @TimothyRoes @khleedril @K4mpfie @ErikJonker @soulsource @pojntfx I guess an alternative is described here: https://github.com/eu-digital-identity-wallet/eudi-app-android-wallet-ui/issues/390

    Uncategorized
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups