Hacker News new | past | comments | ask | show | jobs | submit login

Netflix wants a hardware attestation API to prevent abuse, GrapheneOS can provide that API abstracted through the integrity API, but Google won't authorize it.



This, but notably also: the hardware attestation API will report a device as fully locked down and secured even when a device is infected with a sophisticated-enough piece of malware. Plus, in the past manufacturer keys have leaked but keys have not been revoked.

Hardware attestation is quite useless when a device that hasn't received a single security update in four years is considered safe, but a locked-down ROM implementing everything Google has invented and more is considered dangerous.




Consider applying for YC's Summer 2025 batch! Applications are open till May 13

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: