Hacker News new | ask | show | jobs
by Cider9986 23 days ago
GrapheneOS has an implementation of this with their Auditor app. You can use their service or you can use another Android. No freedom lost, just security gained.

https://attestation.app/about

There's also Android's hardware attestation API which apps can use to verify integrity in a more secure and privacy-respecting way than Google Play Integrity. An increasing number of apps are officially supporting GrapheneOS through this, and that number will only grow as GrapheneOS gains users.

https://grapheneos.org/articles/attestation-compatibility-gu...

2 comments

The auditor app itself does not result in any loss of freedom, but the widespread availability of remote attestation mechanisms on end-user devices incentivizes others to use it in a manner that does.

A purely local mechanism that lets the user check the integrity of their system is great. Making it easy for third parties to inspect it is a severe violation of user freedom and privacy.

> No freedom lost, just security gained

As far as I can tell, it flags unlocked bootloaders? So this is already huge freedom lost.

With grapheneOS you can lock the bootloader with your own keys. Huge difference. (That said, I don't know if the apps which demand the attestation trust anything but the official grapheneOS keys)
Auditor doesn't cause any issues with your system if there's a problem besides letting you know. It's just for informative purposes so you can determine your system is secure.