Hacker News new | ask | show | jobs
by AnthonyMouse 14 days ago
> "The law" requires no such thing

It requires age verification and provides code whose development was subsidized by the government, which third parties the user doesn't control will use, that creates a dependency on those platforms.

> there's nothing preventing those new OSes form providing proper security signals.

A network effect, far from being nothing, is a barrier the height of a mountain.

The purpose of attestation is to lock out competing platforms. It security value is a joke. Devices pass attestation with known vulnerabilities and fail it for being competitors, even if the competitors have better security.

Offering to make attestations nobody accepts is a farce. The problem to be solved is how to run existing software that was originally written for other platforms when the new platform is new and doesn't have enough users for third party developers to specifically target it, which is the exact thing that can't do. And without that it can't get enough users for third party developers to specifically target it.

1 comments

> The purpose of attestation is to lock out competing platforms. It security value is a joke.

This is kind of your... opinion man.

In reality pretty much all security sensitive applications require attestation from their side.

And what security value does that provide, when millions of attestation-passing devices have public unpatched LPE vulnerabilities? Anyone can get one and run arbitrary code on it as root. It's completely worthless for actual security. Worse, it does the opposite, because a newer third party ROM that patches those vulnerabilities would fail attestation, preventing honest users from updating their device and thereby leaving them vulnerable.

What it does do is require you to get one of those devices instead of a competing device or OS, thereby locking out competitors but not attackers.