Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Buying a device that only runs OEN Android is ridiculous for this exact reason.

We need to decouple phone hardware from phone software, as we did with computers.



We do, but I don't see it happening anytime soon. Many banking / government apps and even some games use the Play Integrity API, which AFAIK is starting to require remote attestation for newer devices.

As it's usually not viable to opt-out of those, the solution seems to be having a separate device.


Fortunately (or unfortunately depending on your perspective), Play Integrity is bit of a joke at the moment thanks to a group of OEMs who just can't seem to secure their private keys. Unrevoked keyboxes are publicly available.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: