Hacker News new | ask | show | jobs
by stavros 2 hours ago
You're begging the question. The entire premise of this thread is "we should be able to pay without infesting our phone with corporate malware".
1 comments

Well yes, but attacking Graphene for that is attacking the wrong layer. If you want an open payments system the government has to mandate it, or you could take the low chance of success with the free market competition method.
IMO the most annoying thing is that Google could solve this problem today by just adding the GrapheneOS signing keys to the whitelisted keys. Instead they decide to exclude GrapheneOS because security, while attesting phones that are still on Android 13 (multiple years without fixes for vulnerabilities that are not marked high/critical) and did not apply ASB patches for up to 12 months.

A first step would be requiring Google to attest all devices that have a locked bootloader, verified boot, signed with non-public keys, and have a recent Android version and patch level.

IMO they should also boot anything older than Android 16 and behind more than 1-2 ASBs, if security is the real reason to have Play Integrity remote attestation.

POSIWID: the purpose of remote attestation is to force people to buy devices that pay Google license fees.
>that pay Google license fees

Source? I thought it was free for OEMs?

I think there's a fee and also a long list of requirements - such as you must not sell any phone without Google Play Store.
I read the very first message of the thread as "if you're going to regulate something, regulate that we should be able to pay without requiring Google", ie with Graphene and the like. I didn't read it as an attack on Graphene.