Elektrine lite

← Feed

@pmakholm@social.data.coop

Post #1461966

2026-03-14 14:38 UTC

@anderslund Nogen der kort, men teknisk, kan forklare hvad en app-udvikler får ud af dette API. Ikke bare "det øger sikkerheden - og det er best practise" men "det fjerner denne type angreb på bekostning af denne funktionalitet". Hvorfor er det en god ting og ikke bare en workaround for sikkerhedsteater?

Replies (2)

  • @pmakholm I mine øjne er det en god ting hvis det betyder at man ikke skal tvinges til at underkaste sig googles (eller apples) totalovervågning hvis man vil bruge mobilbank, mobilepay og offentlige apps. Som appudvikler giver det dig potentielt mulighed for at tilbyde din app til brugere som vil have et googlefrit android-system.

    Open ##1461967

  • @pmakholm Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal. https://grapheneos.social/@GrapheneOS/116239523775374959

    Open ##1461987