It requires age verification and provides code whose development was subsidized by the government, which third parties the user doesn't control will use, that creates a dependency on those platforms.
> there's nothing preventing those new OSes form providing proper security signals.
A network effect, far from being nothing, is a barrier the height of a mountain.
The purpose of attestation is to lock out competing platforms. It security value is a joke. Devices pass attestation with known vulnerabilities and fail it for being competitors, even if the competitors have better security.
Offering to make attestations nobody accepts is a farce. The problem to be solved is how to run existing software that was originally written for other platforms when the new platform is new and doesn't have enough users for third party developers to specifically target it, which is the exact thing that can't do. And without that it can't get enough users for third party developers to specifically target it.
And what security value does that provide, when millions of attestation-passing devices have public unpatched LPE vulnerabilities? Anyone can get one and run arbitrary code on it as root. It's completely worthless for actual security. Worse, it does the opposite, because a newer third party ROM that patches those vulnerabilities would fail attestation, preventing honest users from updating their device and thereby leaving them vulnerable.
What it does do is require you to get one of those devices instead of a competing device or OS, thereby locking out competitors but not attackers.
It requires a government-authorised "age verification" "app", but it does not require that it is accessible through standard protocols, so that it can work on any platform. In practice, the governments will only make it available for Android and iOS. Plus, you cannot have a free OS providing "attestation"; "attestation" is incompatible with root access and modifying the OS.
See, you’re just saying what they’re saying, but with emotive, thought-terminating language. Again, it’s easier to complain. Have you been living under a rock for your entire life? Have never ever been involved in a decision being made about certain “blessed” vendors, and the decision is being made for legitimate technical reasons, not “ridiculous” ones.
If you’re the sort of person that’s unable to distinguish between something that’s legitimately unjustifiable/ridiculous, and something that just upsets you, then you do you, but don’t bring this here pretending that it suffices as a discussion, because it doesn’t.
It requires age verification and provides code whose development was subsidized by the government, which third parties the user doesn't control will use, that creates a dependency on those platforms.
> there's nothing preventing those new OSes form providing proper security signals.
A network effect, far from being nothing, is a barrier the height of a mountain.
The purpose of attestation is to lock out competing platforms. It security value is a joke. Devices pass attestation with known vulnerabilities and fail it for being competitors, even if the competitors have better security.
Offering to make attestations nobody accepts is a farce. The problem to be solved is how to run existing software that was originally written for other platforms when the new platform is new and doesn't have enough users for third party developers to specifically target it, which is the exact thing that can't do. And without that it can't get enough users for third party developers to specifically target it.