3 ms·
I'm very surprised Google put in so much effort to implement an approach that is basically the equivalent of client-side verification of passwords. Did no one d
by uqers 1mo ago
I'm very surprised Google put in so much effort to implement an approach that is basically the equivalent of client-side verification of passwords. Did no one designing it mention that it could be defeated by any rooted device?
- demibabs 1mo agoNot any rooted device, it must be rooted via an exploit. Still pretty bad, though
- 12_throw_away 1mo agoActually I think this approach is very forward looking! Attestation is on the cusp of becoming a very powerful technique. We just need to figure out how to build 100% bug-free and 100% secure hardware and software, and then it's gonna work great.
- genxy 1mo agoWait a minute. I think you might have forgotten a /s, I can spot this kinda thing.
- akersten 1mo agoWell, all one has to do is look at the bigger picture of how rooted devices are being shuffled into 3rd rate/totally blocked experiences and the overall direction of things starts to take very clear shape. At over a decade old, still prescient as ever: https://www.youtube.com/watch?v=HUEvRyemKSg https://www.youtube.com/watch?v=HUEvRyemKSg
- RGamma 1mo agoSomeone better figure out how to make computing devices at home from everyday parts because the only way I see this (shockingly rapid) arms race end is legally mandated, cryptographically locked down hardware and software (or even thin clients) everywhere. RMS must be having daily nightmares at this point. P.S.: Fantastic talk you linked there.
- hypfer 1mo agoI think it might tell us something about the culture there by now. Doesn't sound like it's engineering-driven, even though they still do have a lot of capable engineers sitting there and atrophying. I also wouldn't rule out that the less capable ones actually believed that the systems they've built are unrootable or something like that.