Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
AppAttestationz
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
AppAttestationz
5d ago
Any proof for or against a mathematical conjecture, bruteforced by AI can be the spark for new insights. I'll concede that to the AI companies. But I agree with the sentiment that the marketing behind these "discoveries" is d
2.
▲
by
AppAttestationz
16d ago
If you ever start making videos, definitely drop your link below, I love watching repairs videos
3.
▲
by
AppAttestationz
16d ago
Those sound pretty cool! I guess for bike rentals the location is everything though. Surf shop seems chill, I dont know how to surf at all, but I can see myself in onz of those shops too :) I'm not sure how you break into being an elec
4.
▲
by
AppAttestationz
16d ago
Wbu?
5.
▲
by
AppAttestationz
16d ago
I got fired, so I've been enjoying my other hobbies. :) 1. Electronics repairs (Soldering, replacing caps, mosfets etc, lots of fun debugging things) 2. Old timer car repairs (love working on Volkswagen and Saabs) 3. Electrician (hate
6.
▲
by
AppAttestationz
16d ago
I'm waiting for the OpenAI report that their agents defrosted everything.
7.
▲
by
AppAttestationz
19d ago
Isn't v2 completely deprecated? Or are you asking why arent more people using Tor in general? Domain names are random, cant memorize them. Solving that requires centralization or blockchain of some sorts.
8.
▲
by
AppAttestationz
23d ago
"This is what happened to the EU with battery technology, renewable technology, AI, digital services, and semiconductors." I don't agree with the "semiconductor" take of that. ASML, a European company funded by a l
9.
▲
by
AppAttestationz
1mo ago
1. A concern is not invalid merely because something else is worse. 2. Leaping to influence by foreign state is non sequitur. What evidence have you observed for that? How do I know you haven't been sent by the corporate tech elites? 3
10.
▲
by
AppAttestationz
2mo ago
Truth be told, GrapheneOS is the only third party ROM that bothers to make app attestation work.
11.
▲
by
AppAttestationz
2mo ago
Wondering how webauthn extensions will fit into this. PRF for example, takes salts as inputs, if extensions are taken into consideration then it would need to capture input & client extension results too.
12.
▲
by
AppAttestationz
4mo ago
With the amount of changes they've made to WebKit, I honestly don't think we can claim it's just JSC.. https://github.com/oven-sh/WebKit/commits/main/
13.
▲
by
AppAttestationz
4mo ago
I agree with Graphene's take here. I've defended app attestation against baseless criticism, but this is a valid take. The only nuance I would make is that hardware attestation as a technology isn't inherently anti-competitiv
14.
▲
by
AppAttestationz
4mo ago
I suspect that the test suite isn't that great tho. Bun has so many different behaviors compared to other JS engines, sometimes just plain wrong or contradicting the spec. Test suite didnt catch those.. Not sure how much I trust the re
15.
▲
by
AppAttestationz
4mo ago
I suspect that the test suite isn't great. Bun has so many different behaviors compared to other JS engines, sometimes just plain wrong or contradicting the spec. Test suite didnt catch those..
16.
▲
by
AppAttestationz
5mo ago
Notepad+++ was born.
17.
▲
by
AppAttestationz
6mo ago
It's a funny comment, because actual malware, very much loves to tamper with the bootloader and OS. Which was the motivation for cryptographically attesting the boot process and OS, and in part paved the way for app attestation. There
18.
▲
by
AppAttestationz
6mo ago
You can bicker about the words all day long. Legitimacy, or perhaps better: authenticity, in this context, would be a bootloader or OS that doesn't allow tampering with the execution of an app.
19.
▲
by
AppAttestationz
6mo ago
Your whole point is orthogonal to what I said too. I said the title is misleading, which it is. Your argument that app attestation should be avoided because big tech company can withhold it is garbage. It holds no water. They can cut off ac
20.
▲
by
AppAttestationz
6mo ago
I made an account because I'm qualified to talk about this topic :-) I've spent a considerable time testing every corner case of UX, and DX of an app attested service. App attestation can fail on simulators, Graphene OS, dev build
21.
▲
by
AppAttestationz
6mo ago
I agree, there is still a reliance on the tech giants that produce the phones, who are the o'es embedding the cryptographic keys, to make this end to end attestation work. But in pure technical & UX terms, you don't need to be
22.
▲
by
AppAttestationz
6mo ago
I spent months designing a system, exactly like this. An account is not needed, at least for Apple. Play Integrity could the worst offender here, as it can be leveraged to force a user to have installed the app through the Play Store. Indir
23.
▲
by
AppAttestationz
6mo ago
The title is misleading. App attestation does not require an Apple account nor a google account. For Android, it does limit the ROMs to Google certified ones and requires GMS to be installed if Play Integrity is used. An alternative option,