En god nyhed: Unified Attestation - et Google Play Integrity API er under udvikling, iniativ fra @volla og med deltagelse af blandt andet @murena!
-
@MisterSmith @anderslund @murena To quote Voltaire quoting an Italian: "The best is the enemy of the good". Without having much technical insight, I think the initiative by Volla, Murena etc. is trying to fix a problem in a structure none of us created in the first place. So I welcome it.
Do I also want to see a world where tech is structured in a completely different way? Of course. But one step at a time.
And shaming others or wanting them obliterated is not a path to peaceful coexistence
@bettina @MisterSmith @anderslund Android already has a standard hardware attestation API which can be used to permit each of these options. The entire purpose of this system made by Volla, Murena and iodé is to centralize control over what's allowed to be use with a service under their control. The whole point of their service is to permit their own insecure products with no serious security standards while forbidding everything not part of it including GrapheneOS. It's definitely not legal.
-
@bettina @MisterSmith @anderslund Android already has a standard hardware attestation API which can be used to permit each of these options. The entire purpose of this system made by Volla, Murena and iodé is to centralize control over what's allowed to be use with a service under their control. The whole point of their service is to permit their own insecure products with no serious security standards while forbidding everything not part of it including GrapheneOS. It's definitely not legal.
@bettina @MisterSmith @anderslund Forming an anti-competitive cartel which pushes a centralized system only permitting using the products of the companies forming it while disallowing anything else is clearly not legal. We fully intend to file a lawsuit against Volla, Murena and iodé once the damages against GrapheneOS start building up. This highly unethical anti-competitive power grab by these companies will not stand. There's nothing peaceful about this aggressive power grab they're making.
-
@bettina @MisterSmith @anderslund Forming an anti-competitive cartel which pushes a centralized system only permitting using the products of the companies forming it while disallowing anything else is clearly not legal. We fully intend to file a lawsuit against Volla, Murena and iodé once the damages against GrapheneOS start building up. This highly unethical anti-competitive power grab by these companies will not stand. There's nothing peaceful about this aggressive power grab they're making.
@GrapheneOS @bettina @MisterSmith @anderslund I hope you'll file a lawsuit against Google that prevents me to use some apps (banks, mostly) on the system of my choice (i.e. not passing their integrity check), and soon will prevent me to install app from dev who does not want to give all their info to them (i.e. https://keepandroidopen.org/). If that's not anticompetitive cartel behaviour, I dont know what is.
PS : running GrapheneOS here -
@GrapheneOS @bettina @MisterSmith @anderslund I hope you'll file a lawsuit against Google that prevents me to use some apps (banks, mostly) on the system of my choice (i.e. not passing their integrity check), and soon will prevent me to install app from dev who does not want to give all their info to them (i.e. https://keepandroidopen.org/). If that's not anticompetitive cartel behaviour, I dont know what is.
PS : running GrapheneOS here@guilg @bettina @MisterSmith @anderslund We're already taking action against Google for the Play Integrity API. Volla, Murena and iodé have sided against us on freeing people from anti-competitive use of hardware attestation. Instead of fighting it, they've built their own anti-competitive system on top of the standard Android hardware attestation API. They've made it to permit their own products while forbidding others. It's clearly not legal and they don't have the legal resources Google does.
-
@guilg @bettina @MisterSmith @anderslund We're already taking action against Google for the Play Integrity API. Volla, Murena and iodé have sided against us on freeing people from anti-competitive use of hardware attestation. Instead of fighting it, they've built their own anti-competitive system on top of the standard Android hardware attestation API. They've made it to permit their own products while forbidding others. It's clearly not legal and they don't have the legal resources Google does.
@guilg @bettina @MisterSmith @anderslund Google's developer verification system has no direct impact on GrapheneOS since we won't have any enforcement of that system. It's going to be a Google Play feature similar to Play Protect. App developers not performing verification would have grounds to file a lawsuit against them but we wouldn't since it doesn't directly negatively impact us. They've also said there will be a way around it for power users but not how that will work such as needing ADB.
-
@anderslund Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.
-
@anderslund @volla @murena fantastiske nyheder!

@benjaminlj @anderslund Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.
-
@anderslund @volla @murena wohooo!
@Laust Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.
-
@anderslund @volla @murena Sådan! Det er et længe ventet produkt!
@theizo Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.
-
@anderslund Nogen der kort, men teknisk, kan forklare hvad en app-udvikler får ud af dette API.
Ikke bare "det øger sikkerheden - og det er best practise" men "det fjerner denne type angreb på bekostning af denne funktionalitet".
Hvorfor er det en god ting og ikke bare en workaround for sikkerhedsteater?
@pmakholm Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.
-
@anderslund @pmakholm men så kan den stadig hackes fra operativsystemet
@svuorela Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.
-
@anderslund @svuorela @pmakholm jeg er ikke ekspert, men mit indtryk er at det handler om at en server skal vide med sikkerhed at et api kald kommer fra den rigtige app, så man ikke f.eks. kan lave en MenID app som ligner og opfører sig som NemID.
@jpkolsen Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.
-
@svuorela @pmakholm @anderslund Det er ikke nødvendigvis et problem der skal løses. Man kunne også løse det problem, at din bank lider af den opfattelse, at du ikke skal have lov til at tilgå deres selvbetjening fra en computer, du har kontrol over. En opfattelse de sjovt nok kun har for computere i lommeformat
@h0gh Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.
-
@bettina Det ligner at dette i praksis rykker Murena / e/os fra en dries software-freedom a-c til en klart D. Det gør i praksis man ikke kan bruge sin egen modificerede android/linux men er bundet op på nogen andres ubetinget. @anderslund @volla @murena
@svuorela @bettina Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.
-
@bettina @anderslund @volla @murena awesome: “With #UnifiedAttestation, we are creating a transparent and trustworthy procedure for security checks that developers and app publishers can rely on equally. This removes the last hurdle for the use of alternative mobile operating systems"
“We don't want to centralize trust, but organize it transparently and publicly verifiable. When companies check competitors' products, we can strengthen that trust," #unplugtrump #degoogle@MisterSmith Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.
-
@bettina Det ligner at dette i praksis rykker Murena / e/os fra en dries software-freedom a-c til en klart D. Det gør i praksis man ikke kan bruge sin egen modificerede android/linux men er bundet op på nogen andres ubetinget. @anderslund @volla @murena
@svuorela @anderslund Jeg kan ikke se, at det er anderledes end hvad Google gør? Og så synes jeg at den cyber bullying som GOS udfører lige nu, er meget ubehagelig. De siger dels lige ud, at de ikke ønsker at de andre styresystemer overhovedet eksisterer. Og så bliver de ved med at gentage deres egne synspunkter uanset hvad vi andre skriver, og uden at svare rigtigt på kommentarerne. Det er ikke sådan man fører en demokratisk samtale jf. eks. Peter Lauritsen i "På sporet af Hørups demokrati".
-
@svuorela @anderslund Jeg kan ikke se, at det er anderledes end hvad Google gør? Og så synes jeg at den cyber bullying som GOS udfører lige nu, er meget ubehagelig. De siger dels lige ud, at de ikke ønsker at de andre styresystemer overhovedet eksisterer. Og så bliver de ved med at gentage deres egne synspunkter uanset hvad vi andre skriver, og uden at svare rigtigt på kommentarerne. Det er ikke sådan man fører en demokratisk samtale jf. eks. Peter Lauritsen i "På sporet af Hørups demokrati".
@bettina @anderslund det er præcis det samme volla, murena m.fl. som google gør. Men det at en anden gør det gør det ikke bedre.
Det rykker os kun fra en effektivt E til effektivt D på dries - skalaen. Jeg vil højere op. -
@bettina @anderslund det er præcis det samme volla, murena m.fl. som google gør. Men det at en anden gør det gør det ikke bedre.
Det rykker os kun fra en effektivt E til effektivt D på dries - skalaen. Jeg vil højere op.@svuorela Ja, men når Google lukker de andre ude, hvilke alternativer har de så? Jeg vil også hellere leve i en helt anden verden, der passer til mine værdier, men for at citere Voltaire "Det bedste er det godes værste fjende".
-
@svuorela Ja, men når Google lukker de andre ude, hvilke alternativer har de så? Jeg vil også hellere leve i en helt anden verden, der passer til mine værdier, men for at citere Voltaire "Det bedste er det godes værste fjende".
@bettina men graphene vil ikke nøjes med 'D' - det passer ikke med deres model, så de kæmper i mod. Det passer heller ikke til min model.
-
@bettina men graphene vil ikke nøjes med 'D' - det passer ikke med deres model, så de kæmper i mod. Det passer heller ikke til min model.
@svuorela De må kæmpe imod alt det de vil (selv om jeg foretrækker at de kæmper for det de selv vil, og lade de andre om deres). Men jeg bliver altid mistænksom, når folk ikke kan lade deres argumenter stå for sig selv, men i stedet tyr til cyber bullying. Hvis vi accepterer at blive skammet eller mobbet ud af samtalen, så har demokratiet tabt. Det er ikke i orden.
