Andromxda ๐Ÿ‡บ๐Ÿ‡ฆ๐Ÿ‡ต๐Ÿ‡ธ๐Ÿ‡น๐Ÿ‡ผ

65 Followers
251 Following
402 Posts

@khw @vollaficationist @celeduc @GrapheneOS @guilg @EUCommission Centralized remote attestation is diametrically opposed to privacy, since it makes projects vulnerable to pressure to weaken security & privacy, delay updates, etc.

AFAIK the support for remote attestation that is already provided in AOSP does not suffer from this issue, because there is not a single entity that enforces it (banks can whitelist signing key fingerprints).

So the only reason I can think of is control.

@khw @vollaficationist @celeduc @GrapheneOS @guilg @EUCommission This is not just a theoretical concern.

Some European countries border on autocracy. Imagine that this initiative is successful. An autocrat could pressure Volla et al. to only attest phones that have a chat backdoor under the thread of banning them from the market.

It is anti-privacy, anti-security, and anti-freedom.

@khw @danieldk @vollaficationist @celeduc @guilg @EUCommission It has everything to do with a centralized attestation system. Once this system starts being adopted, the EU can require it for banking/government apps as they began the process of doing with the Play Integrity API. They can then hijack it and begin enforcing their own requirements such including disallowing encryption without backdoors. There should be no organization in charge of which devices and operating systems are allowed.

RE: https://mastodon.social/@vollaficationist/116250746129876535

Here's a post where the @vollaficationist clearly refers to themselves as being part of Volla and shares internal information which would only be known to someone working at Volla

This account doesn't belong to someone who uses and supports Volla's products but rather belongs to someone working at the company. Take note of how they claim to respect GrapheneOS at the end of that post. It's an extreme contrast with many of the other posts they've made trying to undermine the GrapheneOS project.

The new MacBook Neo is the most repairable MacBook weโ€™ve seen in 14 years. Screwed-in battery tray, modular ports, sensible layout, and day-one repair manuals. Itโ€™s not perfect, but itโ€™s a real step forward for MacBook repair. Read the full breakdown at the link below.

https://www.ifixit.com/News/116152/macbook-neo-is-the-most-repairable-macbook-in-14-years
โ€”
#iFixit #RightoRepair

Android provides a standard hardware attestation system with support for alternate operating systems via allowing their verified boot key fingerprints. It's mainly used with Google's root of trust and remote key provisioning service but the API supports alternative roots of trust.

Volla's Unified Attestation is fully built on Android's hardware attestation API. It solely exists to create a centralized authority and service determining what's allowed under their control.

https://mastodon.social/@volla/116238706890314617

Jemand, der argumentiert, Forschung sei kein Selbstzweck und hรคtte gefรคlligst der Wirtschaft zu dienen, ist derart weit vom Weg abgekommen, dass er vรถllig ignoriert, dass Wirtschaft kein Selbstzweck ist.

Today's "thank you for your FLOSS contribution" goes out to the people responsible for libfsapfs-utils and fsapfsmount for Linux.

https://www.levlafayette.com/node/785

#apfs #fuse

Accessing APFS on Linux | Lev Lafayette

The Neo is proof that even Apple fear European regulators
https://www.youtube.com/watch?v=PbPCGqoBB4Y
Apple Finally Made a Repairable MacBook?

YouTube

polinaserial-1.1.2 adds ~70 more of recovered iBoot log HMAC mappings (over 600 total now)

https://github.com/NyanSatan/polinaserial

GitHub - NyanSatan/polinaserial: Serial port monitor program for Mac OS X with lolcat, iBoot logs deobfuscation & much more

Serial port monitor program for Mac OS X with lolcat, iBoot logs deobfuscation & much more - NyanSatan/polinaserial

GitHub