zlacker

[parent] [thread] 6 comments
1. ori_b+(OP)[view] [source] 2023-07-26 20:49:02
In other words, it's virtually impossible to use right without also being the entity that hands out phones to users.
replies(1): >>lern_t+Vb
2. lern_t+Vb[view] [source] 2023-07-26 21:44:28
>>ori_b+(OP)
Potentially, a manufacturer could make a multibuild phone where the user could switch between an attested build and a non-attested build and have access to services whose security requires attestation with just a reboot. Otherwise, you would use different devices for different purposes, as I do today. It's unfortunate, but if you really need something that isn't supported by the existing Android APIs, that's the only way.
replies(1): >>ori_b+at
◧◩
3. ori_b+at[view] [source] [discussion] 2023-07-26 23:28:02
>>lern_t+Vb
Or, just don't do remote attestation. The cure is worse than the disease.
replies(2): >>simbol+bB >>lern_t+WB
◧◩◪
4. simbol+bB[view] [source] [discussion] 2023-07-27 00:21:52
>>ori_b+at
That is viable in 2023.

Think about "don't use a smartphone" in 2013. That was viable back then.

It isn't anymore. What you can do is live smartphone-lite, using it only as a secondary device (as grandparent suggested). The same will be true in a couple years (if the big G is successful). Until, then, yea, don't use it, actively campaign against it.

replies(1): >>thefur+6B2
◧◩◪
5. lern_t+WB[view] [source] [discussion] 2023-07-27 00:26:53
>>ori_b+at
Good luck convincing corp security to allow you to use your device on your corporate network without remote attestation.
replies(1): >>ori_b+rO
◧◩◪◨
6. ori_b+rO[view] [source] [discussion] 2023-07-27 01:58:25
>>lern_t+WB
I don't use personal devices on corporate networks. If they want a phone with remote attestation, they can pay for it to sit in a drawer.

Though, at this point I am the founder of my own company. Any software we use will not require attestation. I would be willing to switch vendors over that.

As for web attestation: the software I use regularly needs to run on OpenBSD. It's that simple.

◧◩◪◨
7. thefur+6B2[view] [source] [discussion] 2023-07-27 15:09:38
>>simbol+bB
If this happens the way google wants, I'll have to have a separate physical box set up specifically to access google's shiternet for things like banking and shopping. I'd be glad to stick to websites that have no need or interest for WEI otherwise.

The internet was already going increasingly-downhill anyway.

thisisfine.png

[go to top]