Hacker News new | ask | show | jobs
by xorcist 68 days ago
That is indeed the question: How does attestation help with proving that?

From my limited understanding, I can immediately think of a dozen ways to implement such an attack, and none would be helped by Google attesting that the device is indeed a legitimate Android(tm) device.

It is very hard to understand how this would make any difference juridically. The technical difficulties of avoiding phishing aside, contracts can be contested for a multitude of reasons, including contracts being signed involuntarily.