5 ms·
I'm very surprised Google put in so much effort to implement an approach that is basically the equivalent of client-side verification of passwords. Did no one d
by uqers 22d ago
I'm very surprised Google put in so much effort to implement an approach that is basically the equivalent of client-side verification of passwords. Did no one designing it mention that it could be defeated by any rooted device?
- demibabs 22d agoNot any rooted device, it must be rooted via an exploit. Still pretty bad, though
- 12_throw_away 22d agoActually I think this approach is very forward looking! Attestation is on the cusp of becoming a very powerful technique. We just need to figure out how to build 100% bug-free and 100% secure hardware and software, and then it's gonna work great.
- genxy 22d agoWait a minute. I think you might have forgotten a /s, I can spot this kinda thing.
- akersten 22d agoWell, all one has to do is look at the bigger picture of how rooted devices are being shuffled into 3rd rate/totally blocked experiences and the overall direction of things starts to take very clear shape. At over a decade old, still prescient as ever: https://www.youtube.com/watch?v=HUEvRyemKSg https://www.youtube.com/watch?v=HUEvRyemKSg
- RGamma 21d agoSomeone better figure out how to make computing devices at home from everyday parts because the only way I see this (shockingly rapid) arms race end is legally mandated, cryptographically locked down hardware and software (or even thin clients) everywhere. RMS must be having daily nightmares at this point. P.S.: Fantastic talk you linked there.
- hypfer 22d agoI think it might tell us something about the culture there by now. Doesn't sound like it's engineering-driven, even though they still do have a lot of capable engineers sitting there and atrophying. I also wouldn't rule out that the less capable ones actually believed that the systems they've built are unrootable or something like that.