I agree with that.. additionaly, I'm finding it to be insane that organizations are trying to force you to have a "audited" phone to interact with them. (I.e. events, businesses, etc)
Remote attestation is not just insane, it's the technology that will end free computing as we know it today.
What good is free software if using it marks our devices as untrusted and gets us banned from every service out there? Gets us ostracized from digital society? Because we "tampered" with the device?
We should be able to run whatever software we want and they should be none the wiser. Instead, we are part of the threat model now. Our devices are now cryptographically attesting that they are corporate owned and that we are under corporate control. It's so disgusting. The future we're heading towards is terrifying. Everything the word hacker ever stood for will be destroyed if this keeps up.
It's all about who owns the keys and who trusts those keys. If you don't have the keys to "your" computer, then you don't own that computer, you're just renting it from the corporation.
And even if our own keys could be used, who's going to trust those attestations? Nobody. They will trust Google's keys, Microsoft's keys, Apple's keys. Not ours.
the intent is that no one owns those keys, your silicon should be the only entity in "possession" of those keys.
but no one uses blind signatures for attestation so it can be used to fingerprint your device's serial. they do try to make it hard. but generally you should assume that if whoever you are attesting to colludes with google they will obtain your HWID - and if it's google you are attesting to you should assume they have your HWID.
GOS uses a proxy for attestation, but it does absolutely nothing for this threat model.
PS: DRM is even worse, there is no intermediary and the APIs are open to all apps. you probably need to be a well resourced intel agency to make use of it as you need to source a valid DRM license server certificate. technically, actual license servers are in violation of their agreements with google, apple, etc if they use the license request for fingerprinting. but they do retain the ability to blacklist silicon (invalidate pirate devices from pirated media watermarks).
Yeah same as TPM and Secureboot. They can improve your own personal security (and thereby privacy) drastically, but it has to be controlled by the user.
You'll probably just need to keep two phones. One hostile spying device that you use for authenticating and dealing with government stuff, and that becomes e-waste every 2 years. Then you have one that you can repair and extend for your own stuff that respects you and your privacy.
I am doing this now. I have had a carrier locked iPhone SE 2020 which I only use on Wi-Fi for over five years now. I also have an android phone and I don't install any banking apps on my android phone.
>What good is free software if using it marks our devices as untrusted
That is not what remote attestation is for. The operating system maintains isolation between apps, so a free software app being installed doesn't mean an app that needs high security is compromised.
I think you've misunderstood. It's not an app problem. The problem is that it makes Free Software OSes unviable. The copy of Android you compile and install yourself - or your copy of desktop Linux where you upgraded the kernel yourself - will never pass remote attestation, and it gives both the attestation provider and software that checks attestation the ability to unilaterally shut out any OS they like with no workaround, even those that do pass attestation.
In a world of deeply untrustworthy Big Tech, and trend of governments, banks and other basic services needed to exist in society relying on apps and in the future, websites that use remote attestation, that is very troubling.
There are better ways of dealing with the bad actors problem, but Big Tech has chosen violence.
The hypervisor maintains isolation between operating systems, so a free operating system being installed doesn't mean an app that needs a high security operating system is compromised.
It’s not incompatible with open source. It’s incompatible with free software. If Apple or Google or Microsoft or the government needs to “bless” your build, then you have no freedom to actually use your build.
Your "development build" is another person's daily driver.
Case in point: GrapheneOS (or any other custom Android distro) is unlikely to be able to ever pass remote attestation, even a signed, secure boot build with the bootloader relocked, because it's not the original OS for the hardware.
GrapheneOS implements its own attestation so you can attest that it's real GrapheneOS. The valid approach they've chosen is to try and get on a level playing field with the big guys rather than destroy the playing field. They have a good argument their OS is very secure, so you should accept its attestation. This is how a user-friendly OS backdoors into the attestation system.
I still think destroying the playing field is better, but less likely to succeed.
The whole point of this discussion is the trend towards societal scale denial of that feature by both market forces and governmental forces.
There is no such a thing as "just buy a different device" when this "different device" is actively discriminated against to the point it's a paper weight. I wouldn't be surprised if remote attestation becomes necessary to even get an internet connection in the future.
I miss the days when iOS jailbreaks allowed you to completely circumvent basically all DRM because the trust in Apple was so high that you could just assume a device is secure. Contrast that with Android, which has always had invasive attestation mechanisms because of widespread mistrust in OEMs. On iOS, sometimes you had individual apps trying to check for jailbreak but that was it
We're running into situations where the usage of smart phones and apps are becoming mandatory for using services.
For example: The UK has a digital ID requirement which is required for you to be employed in the UK. Additionally the EU digital identity services have a hardware/software attestitation that is required to run their apps. (Many of those which 3rd party software can't run).
Another example of this is the Australian eTA - (Everyone has to have a visa to visit Australia.. but the real only way to get a visa* is you have to get an electronic travel authorization which only works via an App)
myGov (Australian government app)
gov.br (Brazilian government app)
Ticketcorner
Authy
Chyrpe Dating
TextNow
mada Pay (Saudi NFC payment app)
McDonald's (International app used for many but not all countries not including the US)
Dott
My SEAT (Connectivity for SEAT cars)
SwissID
Volkswagen
BKK Faber-Castell & Partner
TK-Doc
TK-Ident
TK-App (Blocks access to TK-Safe, TK-GesundheitsMessenger, fingerprint login)
IO (Italian government app which uses it to gate access to the digital wallet feature)
PosteID (Italian postal service’s app used to access the national digital identity system "SPID")
Singpass
> The UK has a digital ID requirement which is required for you to be employed in the UK.
That's untrue.
There was a strong push towards the digital ID from the current administration, but it was abandoned 6 months ago.
What you likely mixed up with digital ID is the old digital visa scheme, mandatory for all non-UK citizens to prove right to work.
Re: your app list: looks a little bit eclectic, so it's worth mentioning most of the apps don't ban GoS specifically, but enforce Google play strong or device integrity pass, which GoS doesn't pass.
Some trip on some exploit protections, like secure app spawning, but these can be turned off per app in the latest releases based on Android 17.
I don't know, probably? That always was an offence[1] anyway.
New scheme, mandatory digital ID, would simply stop Britons from being able to use their physical passport to prove they can work. For everyone else that would swap existing electronic-only scheme with another electronic-only scheme.
I don't think anyone half awake would mistake a refugee with a Brit. At least it's not a problem that would explain introducing a whole huge PITA -- like with mandatory IDs for voting: if I'm not mistaken TWO people total were sentenced for voting-related offences, yet we spend double digits of millions of pounds only to (knowingly) disenfranchise voters traditionally voting against the Conservative government.
Look, I'm a citizen of the EU country and my country's physical ID holds electronic layer containing private keys I can use to remotely sign stuff or authenticate myself. It also allows me to using a digital only ID, and the app ecosystem around that is truly amazing. And I'm a picky one.
Basically it's everything, along with basically every single one European physical ID with electronic layer built-in.
British digital ID was *nothing' of that. If it was a physical smartcard first, optional and not mandatory, I'd probably support it, but the government messaging about that was full of lies and handwaving, especially when people were bringing up the failures of digital only systems like Settled Status for Europeans. Nothing mattered, steamrolling over arguments with soundbites.
No, long story short: no, digital IDs are NOT mandatory and no, employment fraud is not that widespread, and the new system won't fix the employers skirting the law.
GrapheneOS and others should have lobbyists or rather lawyers and lawmakers to fight for using secure systems to mandatory be allowed for these. Sure, there must be some type of OS guarantee, but that should not be exclusive to Google and Apple. And indeed browsers with otp/authn devices (not one per service but yubi/thetis type of thing as those can be made sovereign for a large part); when an OS is not allowed, the browser and app should be mandatory allowed with such a device as that is, actually, more secure than the original device as it is an external encryption and encryption key source the hacker cannot reach.
Us users might be effective as well. Hopefully anti-trust law catches up and bans play integrity. They are probably going to spend their money improving features and experience to get more users. There's threads on the forum dedicated to sending emails to Volkswagen to get them to support Grapheneos and it may be working.
> The UK has a digital ID requirement which is required for you to be employed in the UK.
False
In fact I can't think of a single Government service or legal requirement that requires a smartphone in the UK.
In the past year I have applied for a passport, applied for benefits, opened a bank account, passed through border control, filed a company tax return, closed down a business, helped someone else claim for benefits, made police reports, filed a case with the small claims court, paid my council tax, received an incone tax refund, travelled on public transport extensively, hired a car.
All had alternatives as far as I can recall.
Quite a few were done online just with a computer and optionally a phone number
And based on prior discussions here I have to point out that "require" doesn't mean "ok but the alternative is kind of inconvenient"
> We're running into situations where the usage of smart phones and apps are becoming mandatory for using services.
A new building is being built in my city, and the trash containers which were installed outside have instructions printed on them, indicating that you need to use a smartphone app to take out your trash.
I found this deeply offensive in a way that I cannot explain.
Likely referring to Android's Play Integrity/hardware attestation API (good explainer from GrapheneOS [1]) that is practically used to restrict what devices/brands/Android builds an app will allow itself to be run on.
> that organizations are trying to force you to have a "audited" phone to interact with them. (I.e. events, businesses, etc)
Even worse, GOVERNMENTS do that. EU Governments basically forcing you to give Google (via the Google Mobile Services rootkit) or Apple (and via the cloud act also the Trump Admin) access to your entire phone (including all of your saved personal data) to use the govt eID system...
If it were only that and we actually had “free market capitalism” and “competition” you could simply choose, but leering and steering these “organizations” is the treasonous and inherently illegitimate government, which is increasingly indistinguishable from private corporations, mostly because it’s the same pool of people, which are reflexively moving us all towards a common focal point of a form of tyranny similar to hereditary oligarchy and/or serfdom.
What good is free software if using it marks our devices as untrusted and gets us banned from every service out there? Gets us ostracized from digital society? Because we "tampered" with the device?
We should be able to run whatever software we want and they should be none the wiser. Instead, we are part of the threat model now. Our devices are now cryptographically attesting that they are corporate owned and that we are under corporate control. It's so disgusting. The future we're heading towards is terrifying. Everything the word hacker ever stood for will be destroyed if this keeps up.