Apple and Google are gradually expanding their use of hardware-based attestation. They're convincing a growing number of services to adopt it. Google's Play Integrity API and Apple's App Attest API are very similar. Apple brought it to the web via Privacy Pass, which Google intends on doing too.
Leah likes this.
reshared this
M
in reply to GrapheneOS • • •GrapheneOS
in reply to GrapheneOS • • •reshared this
Magical Cat and Rokosun reshared this.
GrapheneOS
in reply to GrapheneOS • • •reshared this
Maria Carole, Irenes (many), Support GrapheneOS 667 and Rokosun reshared this.
GrapheneOS
in reply to GrapheneOS • • •Support GrapheneOS 667 reshared this.
GrapheneOS
in reply to GrapheneOS • • •Google's reCAPTCHA is planning an approach where they use Privacy Pass on Apple hardware, their own approach on Google Mobile Services Android devices and a QR code scanning system to require an iOS or Google certified Android device for Windows and other systems:
support.google.com/recaptcha/a…
reshared this
Francisca Sinn, Pietro395 🇮🇹 and Support GrapheneOS 667 reshared this.
GrapheneOS
in reply to GrapheneOS • • •reshared this
Francisca Sinn, QuadRadical, Shannon Prickett, Support GrapheneOS 667, Kilian Evang, happyborg, Mark Hughes, Magical Cat, María Arias de Reyna, Open Risk and Rokosun reshared this.
GrapheneOS
in reply to GrapheneOS • • •reshared this
Bennett, Meko #nowar and Rune Jensen ✅ 🇳🇴 reshared this.
GrapheneOS
in reply to GrapheneOS • • •reshared this
Pybonacci (no war), jbz, Lady Errant, JWcph, Radicalized By Decency, Magical Cat and Simon Zerafa reshared this.
GrapheneOS
in reply to GrapheneOS • • •reshared this
DNA schedule, jbz, Elischeva, Magical Cat and Lord Caramac the Clueless, KSC reshared this.
GrapheneOS
in reply to GrapheneOS • • •reshared this
7heo, jbz, Lord Caramac the Clueless, KSC and Rokosun reshared this.
GrapheneOS
in reply to GrapheneOS • • •Rokosun reshared this.
GrapheneOS
in reply to GrapheneOS • • •reshared this
AI6YR Ben, DNA schedule, Support GrapheneOS 667, Daniel AJ Sokolov, David Chisnall (*Now with 50% more sarcasm!*) and Rokosun reshared this.
GrapheneOS
in reply to GrapheneOS • • •reshared this
Aral Balkan, Szescstopni, 7heo, Δρομογράφος, Remy Rose, Poujol 𝖱𝗈𝗌𝗍 ✅, Dźwiedziu and Magical Cat reshared this.
GrapheneOS
in reply to GrapheneOS • • •Amber likes this.
reshared this
Bennett, jbz, Mota, Marcus "MajorLinux" Summers, Support GrapheneOS 667, Dawn Ahukanna, Amandine, 7heo, adingbatponder 👾, teemuki, Gerrit 🇪🇺🌍🍉🔻, René, Pietervdvn, lingüista aburrido, Dragofix, sleet01, margot, clarkiestar, Jeremy le fou, Rokosun and Spiralnebel reshared this.
GrapheneOS
in reply to GrapheneOS • • •reshared this
Meko #nowar, Just Ice, Lord Caramac the Clueless, KSC and Rokosun reshared this.
GrapheneOS
in reply to GrapheneOS • • •reshared this
Support GrapheneOS 667, jbz, Jacqueline, happyborg and Lord Caramac the Clueless, KSC reshared this.
GrapheneOS
in reply to GrapheneOS • • •reshared this
DNA schedule, Action Jay 🐾, MJ Ray, Lazarou Monkey Terror 🚀💙🌈, Martin, Support GrapheneOS 667, happyborg, Dźwiedziu and Lord Caramac the Clueless, KSC reshared this.
Linux Is Best
in reply to GrapheneOS • • •It's the goal.
For example, all those new laws for age verification, for example, are to prevent you from using an operating system or ROM that cannot be minored or controlled. Blocking reCAPTCHA on a non-approved, non-certified government and corporate sanctioned devices is just 1 piece of the big picture.
For example, the USA has made any new router not made in the USA illegal to import or sell. The problem is that no mainstream manufacturer currently makes routers in the USA.
Linux Is Best
in reply to GrapheneOS • • •It's the goal.
For example, all those new laws for age verification are to prevent you from using an operating system or ROM that cannot be minored or controlled. Blocking reCAPTCHA on a non-approved, non-certified government and corporate sanctioned devices is just 1 piece of the big picture.
For example, the USA has made any new router not made in the USA illegal to import or sell. They can apply for an exception if they agree to include their new control chip or firmware.
Jacqueline reshared this.
Linux Is Best
in reply to Linux Is Best • • •Motorola has a security contract with the USA.
They will, depending on need, release a device with GrapheneOS — or delay it — and work closely with you to identify the methods and vulnerabilities you discover, as well as how you implement features to overcome the planned “new normal,” so that, behind the scenes, they can undermine and circumvent your work in the future. The investment — which includes you — is intended to strengthen relations and acquire additional contracts. 😭
GrapheneOS
in reply to Linux Is Best • • •Daniël
in reply to Linux Is Best • • •Linux Is Best
in reply to Daniël • • •@danieldk
I am the source.
Both Motorola Mobility with Motorola Solutions CAGE Code: 01113, 6H7Z2, 78205, and 7H229 (NCAGE).
dla.mil/Working-With-DLA/Appli…
If you’re looking for an actual document that says, “Yes, we’re trying to screw over the American people,” a written confession in a convenient PDF file, you won’t find one. Ever.
@GrapheneOS
GrapheneOS
in reply to Linux Is Best • • •Linux Is Best
in reply to GrapheneOS • • •@danieldk
Yes, and money goes both ways.
thomas
in reply to GrapheneOS • • •GrapheneOS
in reply to thomas • • •Ox1de
in reply to GrapheneOS • • •Papageier
in reply to GrapheneOS • • •Google has the entirety of its commercial success thanks to the openness and interoperability of the #WWW. To try an captcha it to build a walled garden is, frankly speaking, an act of disrespect for @timbl and the entire web community.
Microsoft has tried it. Apple has tried it as well. Both have finally had the insight that working with the community is much more rewarding and profitable than working against it.
Let's work toward Google having that same revelation as well.
(Sorry for the pun, couldn't resist)
Lord Caramac the Clueless, KSC reshared this.
GrapheneOS
in reply to GrapheneOS • • •Unified Attestation is another anti-competitive system being pushed by multiple European companies. It will similarly lock people out from using arbitrary hardware and software. That's not a solution and is far worse than Android's much more open hardware attestation API.
grapheneos.social/@GrapheneOS/…
GrapheneOS
Unified Attestation is another anti-competitive system being pushed by multiple European companies. It will similarly lock people out from using arbitrary hardware and software. That's not a solution and is far worse than Android's much more open hardware attestation API.
grapheneos.social/@GrapheneOS/…
GrapheneOS
2026-03-16 15:19:34
reshared this
Rokosun reshared this.
GrapheneOS
in reply to GrapheneOS • • •reshared this
Just Ice and Rokosun reshared this.
M/KΞ
in reply to GrapheneOS • • •Lord Caramac the Clueless, KSC reshared this.
vvanag
in reply to GrapheneOS • • •Resilience Theatre
in reply to GrapheneOS • • •Matúš
in reply to GrapheneOS • • •LosOS · GitLab
GitLabGrapheneOS
in reply to Matúš • • •GrapheneOS
in reply to GrapheneOS • • •Lord Caramac the Clueless, KSC reshared this.
GrapheneOS
in reply to GrapheneOS • • •Lord Caramac the Clueless, KSC reshared this.
Mr. Scam Likely
in reply to GrapheneOS • • •vonKordke
in reply to GrapheneOS • • •Governments should take that apart immediately, but they are powerless cowards.
d@nny disc@
in reply to GrapheneOS • • •Eric Lawton
in reply to d@nny disc@ • • •@hipsterelectron
And "national security" is in turn a euphemism for "rulers' security".
@GrapheneOS @dwaynemonroe
adingbatponder 👾
in reply to GrapheneOS • • •Douglas
in reply to GrapheneOS • • •The Brazilian government app "gov.br" requires Play Integrity too. There's no fallback, no alternative verification method.
I've sent complaints to the Brazilian entities suggested in the "Keep Android Open" website, but they either reply with a template message or completely ignore it.
Google is pretty much our Evil Corp, but where is fsociety? 👹
Profile13115
in reply to GrapheneOS • • •eske
in reply to GrapheneOS • • •Tim Panton
in reply to GrapheneOS • • •Magical Cat
in reply to GrapheneOS • • •G̸u̸a̸l̸t̸i̸e̸r̸o̸
in reply to GrapheneOS • • •🏳️🌈 Brie 🪰🚴🌸✨
in reply to G̸u̸a̸l̸t̸i̸e̸r̸o̸ • • •GrapheneOS
in reply to 🏳️🌈 Brie 🪰🚴🌸✨ • • •Morgan ⚧️
in reply to GrapheneOS • • •Ra
in reply to GrapheneOS • • •June [⚦257-⚧213-⚩099]
in reply to Ra • • •@Ra I can't use the online services of my healthcare provider on my desktop (cant login on their website) without having their app on an android or apple device. I'am effectively being locked out of all of their online services (except contacting them via email).
germany here
Inanna🇵🇸
in reply to GrapheneOS • • •GrapheneOS
in reply to Inanna🇵🇸 • • •@FantasmitaAsex reCAPTCHA is extremely widely adopted. A portion of services using alternatives won't solve how much damage they can do to alternatives via control of reCAPTCHA.
Only a tiny proportion of apps use the Play Integrity API and ban GrapheneOS with it. It's only around 1/10 banking apps and perhaps 3/10 government apps, but the overall picture more like 1/10000 apps or even lower. However, it's widely adopted enough that it's a huge barrier to GrapheneOS adoption for people already.
GrapheneOS
in reply to Inanna🇵🇸 • • •@FantasmitaAsex reCAPTCHA is extremely widely adopted. A portion of services using alternatives won't solve how much damage they can do to alternatives via control of reCAPTCHA.
Only a tiny proportion of apps use the Play Integrity API and ban GrapheneOS with it. It's something like 1/10000 apps or even lower but for banking apps it's around 1/10 and important government apps around 2/10. However, it's widely adopted enough that it's a huge barrier to GrapheneOS adoption for people already.
Inanna🇵🇸 reshared this.
Garrett LeSage
in reply to GrapheneOS • • •My bank has been this way for months already. They got rid of other 2FA methods they used to support and require a Google-approved Android OS or iOS... even to log in to their banking UI on a desktop/laptop.
It's infuriating, and it means I'm now 100% locked in to a proprietary app on a proprietary OS (controlled by 1 of 2 companies, both headquartered in California, USA) on a proprietary phone for banking and public transit (in Europe), with no alternative possible. 😖
GrapheneOS
in reply to Garrett LeSage • • •Support GrapheneOS 667 reshared this.
GrapheneOS
in reply to GrapheneOS • • •GrapheneOS attestation compatibility guide
GrapheneOSDidek
in reply to GrapheneOS • • •@garrett
Hardware Attestation should only be used in situation when device is supposed to not be owned by the user. Like an internal service of a company making sure only company-provided devices are accessing it.
Magical Cat
in reply to GrapheneOS • • •Bank I am customer of, in a EU-candidate country, when add some services, makes them available only from mobile device. For example, purchase of travel insurance, which normally happens beforehand, not during travel itself.
I don't see a logical reason to limit a service availability to a weaker in UX sense mobile platform with small screen, half if it usually eaten by on-screen keyboard, and lack of proper mouse/keyboard).
Arthur van der Harg
in reply to GrapheneOS • • •ee
in reply to Arthur van der Harg • • •Arthur van der Harg
in reply to ee • • •ee
in reply to Arthur van der Harg • • •Arthur van der Harg
in reply to ee • • •ee
in reply to Arthur van der Harg • • •Arthur van der Harg
in reply to ee • • •TheZorse
in reply to GrapheneOS • • •I wonder of there's someone you can contact in the Canadian government to try to hard-block this from becoming a requirement with our government, banks, etc., from a national security perspective. You might find a receptive audience given that we're trying to gain some independence from the US.
My feeling is that the government knows that reliance on American tech is a problem and a trap, but they don't have a good grasp of the details or the alternatives.
Buridan's procrastinator ⁂
in reply to GrapheneOS • • •GrapheneOS
Unknown parent • • •Daniel
in reply to GrapheneOS • • •@EUCommission is that the digital independece we want for the #EU ?
(read the whole thread)
Edit: @EC_DIGIT_director_general i guess it's interesting for you and your department as well.
GrapheneOS
Unknown parent • • •@7cd4a72311bad46117e0f692dddc5f31a543b47ff4265b028f8d820ac808ab3c @MAlBarram Pixels aren't somehow dead and none of what we posted is in any way specific to Pixels, Android devices or operating systems based on the Android Open Source Project.
You should read the thread we posted which is about them bringing the Play Integrity API to the web including for desktops by requiring having a phone certified by it or an iOS device in order to pass checks on the web and desktops too.
Demi Marie Obenour
in reply to GrapheneOS • • •DFX4509B (Joshua Mason)
in reply to Demi Marie Obenour • •Jay 🚩
in reply to GrapheneOS • • •GrapheneOS
in reply to Jay 🚩 • • •Jay 🚩 reshared this.
DFX4509B (Joshua Mason)
in reply to GrapheneOS • •Andreas K
in reply to GrapheneOS • • •There are IMHO few cars when hardware attestation (which btw is the ultimate in anti handicapped stance one can take, I literally remember a decade ago how a colleague modified his Linux workstation to deal with his personal mix of handicaps)
And if there is a need for that there is no need to go with a vendor lock-in solution as the grapheneos crew correctly points out.
But security theater is cheaper than haviyng real competent engineer look over the security design for real.
Sub_Root
in reply to GrapheneOS • • •Hardened OSs like #GrapheneOS do a great job, but we have a major blind spot: The Hardware.
Modern phones are networks of dozens of "black box" computers (UFS, Baseband, Wi-Fi) running proprietary code we can't audit, disable, secure or replace.
Why this matters:
1️⃣ Persistence: Malware in your UFS/SSD controller survives a factory reset.
2️⃣ Tracking: Hardware Attestation acts as an immutable digital fingerprint.
3️⃣ Shadow Attacks: Zero-click exploits hit your Wi-Fi or Baseband before the OS can even react.
We are calling for #HardwareSovereignty. Inspired by the #OpenBSD philosophy, we demand:
✅ Open & replaceable firmware for ALL subsystems.
✅ User-controlled hardware toggles.
✅ Trust minimization that includes the manufacturer.
It's time to move from "Vendor-Enforced Security" to User Sovere
... Show more...Hardened OSs like #GrapheneOS do a great job, but we have a major blind spot: The Hardware.
Modern phones are networks of dozens of "black box" computers (UFS, Baseband, Wi-Fi) running proprietary code we can't audit, disable, secure or replace.
Why this matters:
1️⃣ Persistence: Malware in your UFS/SSD controller survives a factory reset.
2️⃣ Tracking: Hardware Attestation acts as an immutable digital fingerprint.
3️⃣ Shadow Attacks: Zero-click exploits hit your Wi-Fi or Baseband before the OS can even react.
We are calling for #HardwareSovereignty. Inspired by the #OpenBSD philosophy, we demand:
✅ Open & replaceable firmware for ALL subsystems.
✅ User-controlled hardware toggles.
✅ Trust minimization that includes the manufacturer.
It's time to move from "Vendor-Enforced Security" to User Sovereignty.
Read the full Open Letter here: pastebin.com/RzRbzhwn
#HardwareSovereignty #Infosec #CyberSecurity #Privacy #OpenSource #TechFreedom
A Call for User-Centric Hardware Sovereignty - Pastebin.com
Pastebin