Hacker News new | ask | show | jobs
by izacus 14 days ago
> The purpose of attestation is to lock out competing platforms. It security value is a joke.

This is kind of your... opinion man.

In reality pretty much all security sensitive applications require attestation from their side.

1 comments

And what security value does that provide, when millions of attestation-passing devices have public unpatched LPE vulnerabilities? Anyone can get one and run arbitrary code on it as root. It's completely worthless for actual security. Worse, it does the opposite, because a newer third party ROM that patches those vulnerabilities would fail attestation, preventing honest users from updating their device and thereby leaving them vulnerable.

What it does do is require you to get one of those devices instead of a competing device or OS, thereby locking out competitors but not attackers.