En god nyhed: Unified Attestation - et Google Play Integrity API alternativ er under udvikling, iniativ fra @volla og med deltagelse af blandt andet @murena!

https://uattest.net/

Brug det i din app, og fortæl din bank, mobliepay, digitaliseringsstyrelsen og alle mulige andre om det :-)

#engodting #opensource #alternative

Unified Attestation

Unified Attestation is a free, open-source alternative to Google Play Integrity with offline verification and simple app + server integration.

@anderslund @volla @murena Jeg kunne ikke lige se af linket, at Murena også deltager?
@bettina @volla @murena hehe, det kommer fra nicks (the linuxexperiement ) seneste video, hvor han omtaler det.
@anderslund @volla @murena Ok, tak! Jeg fik også et svar i murena-community men har ikke fået læst det endnu: https://community.e.foundation/t/article-paying-without-google/80205
ARTICLE: Paying without Google

Paying without Google: New consortium wants to remove custom ROM hurdles Using banking and payment apps on Android smartphones with custom ROMs is a problem: A European industry consortium now wants to change that. Full article here: Paying without Google: New consortium wants to remove custom ROM hurdles | heise online Regain your privacy! Adopt /e/OS the deGoogled mobile OS and online services

/e/OS community
@bettina Det ligner at dette i praksis rykker Murena / e/os fra en dries software-freedom a-c til en klart D. Det gør i praksis man ikke kan bruge sin egen modificerede android/linux men er bundet op på nogen andres ubetinget. @anderslund @volla @murena

@svuorela @bettina Android already has a hardware attestation system open to everyone unlike this centralized system. Volla, Murena and iodé made a centralized system on top of the Android hardware attestation API to permit their own products while forbidding others. They're not enabling anything which wasn't already possible and are fully dependent on standard Android hardware attestation. Unified Attestation is anti-competitive and it clearly isn't legal.

https://grapheneos.social/@GrapheneOS/116239523775374959

GrapheneOS (@[email protected])

Android provides a standard hardware attestation system with support for alternate operating systems via allowing their verified boot key fingerprints. It's mainly used with Google's root of trust and remote key provisioning service but the API supports alternative roots of trust. Volla's Unified Attestation is fully built on Android's hardware attestation API. It solely exists to create a centralized authority and service determining what's allowed under their control. https://mastodon.social/@volla/116238706890314617

GrapheneOS Mastodon