this post was submitted on 19 Oct 2024
6 points (100.0% liked)
Privacy
1 readers
16 users here now
Everything about privacy (the confidentiality pillar of security) -- but not restricted to infosec. Offline privacy is also relevant here.
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
@[email protected]
GrapheneOS fully supports hardware-based attestation. Google is entirely capable of verifying a device runs the genuine GrapheneOS releases:
https://grapheneos.org/articles/attestation-compatibility-guide
Play Integrity API has nothing to do with security regardless of how it's marketed. It allows a device to pass if it hasn't received security patches for 8 years. All it does is check if it's a Google certified device and tries to stop spoofing within constraints of allowing highly insecure, ancient devices to pass.