Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. En god nyhed: Unified Attestation - et Google Play Integrity API er under udvikling, iniativ fra @volla og med deltagelse af blandt andet @murena!

En god nyhed: Unified Attestation - et Google Play Integrity API er under udvikling, iniativ fra @volla og med deltagelse af blandt andet @murena!

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
engodtingopensourcealternative
72 Indlæg 16 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • mistersmith@mastodon.socialM mistersmith@mastodon.social

    @bettina @anderslund @volla @murena awesome: “With #UnifiedAttestation, we are creating a transparent and trustworthy procedure for security checks that developers and app publishers can rely on equally. This removes the last hurdle for the use of alternative mobile operating systems"
    “We don't want to centralize trust, but organize it transparently and publicly verifiable. When companies check competitors' products, we can strengthen that trust," #unplugtrump #degoogle

    https://www.heise.de/en/news/Paying-without-Google-New-consortium-wants-to-remove-custom-ROM-hurdles-11204037.html

    mistersmith@mastodon.socialM This user is from outside of this forum
    mistersmith@mastodon.socialM This user is from outside of this forum
    mistersmith@mastodon.social
    wrote sidst redigeret af
    #29

    RE: https://grapheneos.social/@GrapheneOS/116200110686604617

    @bettina @anderslund @volla @murena just read the protest from GrapheneOS: https://mastodon.social/@GrapheneOS@grapheneos.social/116200111659862792

    I cannot see through the technical background how this system closes the space and just deamercanizes it, being from EU.

    https://www.heise.de/en/news/Paying-without-Google-New-consortium-wants-to-remove-custom-ROM-hurdles-11204037.html

    bettina@mastodon.nuB 1 Reply Last reply
    0
    • mistersmith@mastodon.socialM mistersmith@mastodon.social

      RE: https://grapheneos.social/@GrapheneOS/116200110686604617

      @bettina @anderslund @volla @murena just read the protest from GrapheneOS: https://mastodon.social/@GrapheneOS@grapheneos.social/116200111659862792

      I cannot see through the technical background how this system closes the space and just deamercanizes it, being from EU.

      https://www.heise.de/en/news/Paying-without-Google-New-consortium-wants-to-remove-custom-ROM-hurdles-11204037.html

      bettina@mastodon.nuB This user is from outside of this forum
      bettina@mastodon.nuB This user is from outside of this forum
      bettina@mastodon.nu
      wrote sidst redigeret af
      #30

      @MisterSmith @anderslund @murena To quote Voltaire quoting an Italian: "The best is the enemy of the good". Without having much technical insight, I think the initiative by Volla, Murena etc. is trying to fix a problem in a structure none of us created in the first place. So I welcome it.

      Do I also want to see a world where tech is structured in a completely different way? Of course. But one step at a time.

      And shaming others or wanting them obliterated is not a path to peaceful coexistence

      mistersmith@mastodon.socialM grapheneos@grapheneos.socialG xtreix@infosec.exchangeX 3 Replies Last reply
      1
      0
      • bettina@mastodon.nuB bettina@mastodon.nu

        @MisterSmith @anderslund @murena To quote Voltaire quoting an Italian: "The best is the enemy of the good". Without having much technical insight, I think the initiative by Volla, Murena etc. is trying to fix a problem in a structure none of us created in the first place. So I welcome it.

        Do I also want to see a world where tech is structured in a completely different way? Of course. But one step at a time.

        And shaming others or wanting them obliterated is not a path to peaceful coexistence

        mistersmith@mastodon.socialM This user is from outside of this forum
        mistersmith@mastodon.socialM This user is from outside of this forum
        mistersmith@mastodon.social
        wrote sidst redigeret af
        #31

        @bettina @anderslund @murena thank you for furthering :]

        1 Reply Last reply
        0
        • anderslund@expressional.socialA anderslund@expressional.social

          En god nyhed: Unified Attestation - et Google Play Integrity API alternativ er under udvikling, iniativ fra @volla og med deltagelse af blandt andet @murena!

          https://uattest.net/

          Brug det i din app, og fortæl din bank, mobliepay, digitaliseringsstyrelsen og alle mulige andre om det 🙂

          #engodting #opensource #alternative

          grapheneos@grapheneos.socialG This user is from outside of this forum
          grapheneos@grapheneos.socialG This user is from outside of this forum
          grapheneos@grapheneos.social
          wrote sidst redigeret af
          #32

          @anderslund All they're doing is building a centralized system on top of standard hardware attestation permitting only their products regardless of how insecure those are. Unified Attestation anti-competitive and clearly illegal. If any app implements this without permitting GrapheneOS via standard Android hardware attestation, that's going to be a problem for each of the companies involved. They aren't allowed to ban using products from other companies.

          https://grapheneos.social/@GrapheneOS/116200110686604617

          1 Reply Last reply
          0
          • mistersmith@mastodon.socialM mistersmith@mastodon.social

            @bettina @anderslund @volla @murena awesome: “With #UnifiedAttestation, we are creating a transparent and trustworthy procedure for security checks that developers and app publishers can rely on equally. This removes the last hurdle for the use of alternative mobile operating systems"
            “We don't want to centralize trust, but organize it transparently and publicly verifiable. When companies check competitors' products, we can strengthen that trust," #unplugtrump #degoogle

            https://www.heise.de/en/news/Paying-without-Google-New-consortium-wants-to-remove-custom-ROM-hurdles-11204037.html

            grapheneos@grapheneos.socialG This user is from outside of this forum
            grapheneos@grapheneos.socialG This user is from outside of this forum
            grapheneos@grapheneos.social
            wrote sidst redigeret af
            #33

            @MisterSmith @bettina @anderslund All they're doing is building a centralized system on top of standard hardware attestation permitting only their products regardless of how insecure those are. Unified Attestation anti-competitive and clearly illegal. If any app implements this without permitting GrapheneOS via standard Android hardware attestation, that's going to be a problem for each of the companies involved. They aren't allowed to ban using products from other companies.

            1 Reply Last reply
            0
            • bettina@mastodon.nuB bettina@mastodon.nu

              @MisterSmith @anderslund @murena To quote Voltaire quoting an Italian: "The best is the enemy of the good". Without having much technical insight, I think the initiative by Volla, Murena etc. is trying to fix a problem in a structure none of us created in the first place. So I welcome it.

              Do I also want to see a world where tech is structured in a completely different way? Of course. But one step at a time.

              And shaming others or wanting them obliterated is not a path to peaceful coexistence

              grapheneos@grapheneos.socialG This user is from outside of this forum
              grapheneos@grapheneos.socialG This user is from outside of this forum
              grapheneos@grapheneos.social
              wrote sidst redigeret af
              #34

              @bettina @MisterSmith @anderslund Android already has a standard hardware attestation API which can be used to permit each of these options. The entire purpose of this system made by Volla, Murena and iodé is to centralize control over what's allowed to be use with a service under their control. The whole point of their service is to permit their own insecure products with no serious security standards while forbidding everything not part of it including GrapheneOS. It's definitely not legal.

              grapheneos@grapheneos.socialG 1 Reply Last reply
              0
              • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                @bettina @MisterSmith @anderslund Android already has a standard hardware attestation API which can be used to permit each of these options. The entire purpose of this system made by Volla, Murena and iodé is to centralize control over what's allowed to be use with a service under their control. The whole point of their service is to permit their own insecure products with no serious security standards while forbidding everything not part of it including GrapheneOS. It's definitely not legal.

                grapheneos@grapheneos.socialG This user is from outside of this forum
                grapheneos@grapheneos.socialG This user is from outside of this forum
                grapheneos@grapheneos.social
                wrote sidst redigeret af
                #35

                @bettina @MisterSmith @anderslund Forming an anti-competitive cartel which pushes a centralized system only permitting using the products of the companies forming it while disallowing anything else is clearly not legal. We fully intend to file a lawsuit against Volla, Murena and iodé once the damages against GrapheneOS start building up. This highly unethical anti-competitive power grab by these companies will not stand. There's nothing peaceful about this aggressive power grab they're making.

                guilg@piaille.frG 1 Reply Last reply
                0
                • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                  @bettina @MisterSmith @anderslund Forming an anti-competitive cartel which pushes a centralized system only permitting using the products of the companies forming it while disallowing anything else is clearly not legal. We fully intend to file a lawsuit against Volla, Murena and iodé once the damages against GrapheneOS start building up. This highly unethical anti-competitive power grab by these companies will not stand. There's nothing peaceful about this aggressive power grab they're making.

                  guilg@piaille.frG This user is from outside of this forum
                  guilg@piaille.frG This user is from outside of this forum
                  guilg@piaille.fr
                  wrote sidst redigeret af
                  #36

                  @GrapheneOS @bettina @MisterSmith @anderslund I hope you'll file a lawsuit against Google that prevents me to use some apps (banks, mostly) on the system of my choice (i.e. not passing their integrity check), and soon will prevent me to install app from dev who does not want to give all their info to them (i.e. https://keepandroidopen.org/). If that's not anticompetitive cartel behaviour, I dont know what is.
                  PS : running GrapheneOS here

                  grapheneos@grapheneos.socialG 1 Reply Last reply
                  1
                  0
                  • guilg@piaille.frG guilg@piaille.fr

                    @GrapheneOS @bettina @MisterSmith @anderslund I hope you'll file a lawsuit against Google that prevents me to use some apps (banks, mostly) on the system of my choice (i.e. not passing their integrity check), and soon will prevent me to install app from dev who does not want to give all their info to them (i.e. https://keepandroidopen.org/). If that's not anticompetitive cartel behaviour, I dont know what is.
                    PS : running GrapheneOS here

                    grapheneos@grapheneos.socialG This user is from outside of this forum
                    grapheneos@grapheneos.socialG This user is from outside of this forum
                    grapheneos@grapheneos.social
                    wrote sidst redigeret af
                    #37

                    @guilg @bettina @MisterSmith @anderslund We're already taking action against Google for the Play Integrity API. Volla, Murena and iodé have sided against us on freeing people from anti-competitive use of hardware attestation. Instead of fighting it, they've built their own anti-competitive system on top of the standard Android hardware attestation API. They've made it to permit their own products while forbidding others. It's clearly not legal and they don't have the legal resources Google does.

                    grapheneos@grapheneos.socialG 1 Reply Last reply
                    0
                    • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                      @guilg @bettina @MisterSmith @anderslund We're already taking action against Google for the Play Integrity API. Volla, Murena and iodé have sided against us on freeing people from anti-competitive use of hardware attestation. Instead of fighting it, they've built their own anti-competitive system on top of the standard Android hardware attestation API. They've made it to permit their own products while forbidding others. It's clearly not legal and they don't have the legal resources Google does.

                      grapheneos@grapheneos.socialG This user is from outside of this forum
                      grapheneos@grapheneos.socialG This user is from outside of this forum
                      grapheneos@grapheneos.social
                      wrote sidst redigeret af
                      #38

                      @guilg @bettina @MisterSmith @anderslund Google's developer verification system has no direct impact on GrapheneOS since we won't have any enforcement of that system. It's going to be a Google Play feature similar to Play Protect. App developers not performing verification would have grounds to file a lawsuit against them but we wouldn't since it doesn't directly negatively impact us. They've also said there will be a way around it for power users but not how that will work such as needing ADB.

                      1 Reply Last reply
                      0
                      • anderslund@expressional.socialA anderslund@expressional.social

                        En god nyhed: Unified Attestation - et Google Play Integrity API alternativ er under udvikling, iniativ fra @volla og med deltagelse af blandt andet @murena!

                        https://uattest.net/

                        Brug det i din app, og fortæl din bank, mobliepay, digitaliseringsstyrelsen og alle mulige andre om det 🙂

                        #engodting #opensource #alternative

                        grapheneos@grapheneos.socialG This user is from outside of this forum
                        grapheneos@grapheneos.socialG This user is from outside of this forum
                        grapheneos@grapheneos.social
                        wrote sidst redigeret af
                        #39

                        @anderslund Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                        https://grapheneos.social/@GrapheneOS/116239523775374959

                        1 Reply Last reply
                        0
                        • benjaminlj@virup.socialB benjaminlj@virup.social

                          @anderslund @volla @murena fantastiske nyheder!

                          grapheneos@grapheneos.socialG This user is from outside of this forum
                          grapheneos@grapheneos.socialG This user is from outside of this forum
                          grapheneos@grapheneos.social
                          wrote sidst redigeret af
                          #40

                          @benjaminlj @anderslund Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                          https://grapheneos.social/@GrapheneOS/116239523775374959

                          1 Reply Last reply
                          0
                          • laust@ohai.socialL laust@ohai.social

                            @anderslund @volla @murena wohooo!

                            grapheneos@grapheneos.socialG This user is from outside of this forum
                            grapheneos@grapheneos.socialG This user is from outside of this forum
                            grapheneos@grapheneos.social
                            wrote sidst redigeret af
                            #41

                            @Laust Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                            https://grapheneos.social/@GrapheneOS/116239523775374959

                            1 Reply Last reply
                            0
                            • theizo@helvede.netT theizo@helvede.net

                              @anderslund @volla @murena Sådan! Det er et længe ventet produkt!

                              grapheneos@grapheneos.socialG This user is from outside of this forum
                              grapheneos@grapheneos.socialG This user is from outside of this forum
                              grapheneos@grapheneos.social
                              wrote sidst redigeret af
                              #42

                              @theizo Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                              https://grapheneos.social/@GrapheneOS/116239523775374959

                              1 Reply Last reply
                              0
                              • pmakholm@social.data.coopP pmakholm@social.data.coop

                                @anderslund Nogen der kort, men teknisk, kan forklare hvad en app-udvikler får ud af dette API.

                                Ikke bare "det øger sikkerheden - og det er best practise" men "det fjerner denne type angreb på bekostning af denne funktionalitet".

                                Hvorfor er det en god ting og ikke bare en workaround for sikkerhedsteater?

                                grapheneos@grapheneos.socialG This user is from outside of this forum
                                grapheneos@grapheneos.socialG This user is from outside of this forum
                                grapheneos@grapheneos.social
                                wrote sidst redigeret af
                                #43

                                @pmakholm Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                                https://grapheneos.social/@GrapheneOS/116239523775374959

                                1 Reply Last reply
                                0
                                • svuorela@helvede.netS svuorela@helvede.net

                                  @anderslund @pmakholm men så kan den stadig hackes fra operativsystemet

                                  grapheneos@grapheneos.socialG This user is from outside of this forum
                                  grapheneos@grapheneos.socialG This user is from outside of this forum
                                  grapheneos@grapheneos.social
                                  wrote sidst redigeret af
                                  #44

                                  @svuorela Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                                  https://grapheneos.social/@GrapheneOS/116239523775374959

                                  1 Reply Last reply
                                  0
                                  • jpkolsen@social.data.coopJ jpkolsen@social.data.coop

                                    @anderslund @svuorela @pmakholm jeg er ikke ekspert, men mit indtryk er at det handler om at en server skal vide med sikkerhed at et api kald kommer fra den rigtige app, så man ikke f.eks. kan lave en MenID app som ligner og opfører sig som NemID.

                                    grapheneos@grapheneos.socialG This user is from outside of this forum
                                    grapheneos@grapheneos.socialG This user is from outside of this forum
                                    grapheneos@grapheneos.social
                                    wrote sidst redigeret af
                                    #45

                                    @jpkolsen Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                                    https://grapheneos.social/@GrapheneOS/116239523775374959

                                    1 Reply Last reply
                                    0
                                    • h0gh@mastodon.socialH h0gh@mastodon.social

                                      @svuorela @pmakholm @anderslund Det er ikke nødvendigvis et problem der skal løses. Man kunne også løse det problem, at din bank lider af den opfattelse, at du ikke skal have lov til at tilgå deres selvbetjening fra en computer, du har kontrol over. En opfattelse de sjovt nok kun har for computere i lommeformat

                                      grapheneos@grapheneos.socialG This user is from outside of this forum
                                      grapheneos@grapheneos.socialG This user is from outside of this forum
                                      grapheneos@grapheneos.social
                                      wrote sidst redigeret af
                                      #46

                                      @h0gh Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                                      https://grapheneos.social/@GrapheneOS/116239523775374959

                                      1 Reply Last reply
                                      0
                                      • svuorela@helvede.netS svuorela@helvede.net

                                        @bettina Det ligner at dette i praksis rykker Murena / e/os fra en dries software-freedom a-c til en klart D. Det gør i praksis man ikke kan bruge sin egen modificerede android/linux men er bundet op på nogen andres ubetinget. @anderslund @volla @murena

                                        grapheneos@grapheneos.socialG This user is from outside of this forum
                                        grapheneos@grapheneos.socialG This user is from outside of this forum
                                        grapheneos@grapheneos.social
                                        wrote sidst redigeret af
                                        #47

                                        @svuorela @bettina Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                                        https://grapheneos.social/@GrapheneOS/116239523775374959

                                        1 Reply Last reply
                                        0
                                        • mistersmith@mastodon.socialM mistersmith@mastodon.social

                                          @bettina @anderslund @volla @murena awesome: “With #UnifiedAttestation, we are creating a transparent and trustworthy procedure for security checks that developers and app publishers can rely on equally. This removes the last hurdle for the use of alternative mobile operating systems"
                                          “We don't want to centralize trust, but organize it transparently and publicly verifiable. When companies check competitors' products, we can strengthen that trust," #unplugtrump #degoogle

                                          https://www.heise.de/en/news/Paying-without-Google-New-consortium-wants-to-remove-custom-ROM-hurdles-11204037.html

                                          grapheneos@grapheneos.socialG This user is from outside of this forum
                                          grapheneos@grapheneos.socialG This user is from outside of this forum
                                          grapheneos@grapheneos.social
                                          wrote sidst redigeret af
                                          #48

                                          @MisterSmith Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

                                          https://grapheneos.social/@GrapheneOS/116239523775374959

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper