GrapheneOS on Nostr: Morten If they insist on verifying device/OS integrity, then they need to read ...
Morten (nprofile…uwp2) If they insist on verifying device/OS integrity, then they need to read
https://grapheneos.org/articles/attestation-compatibility-guide which explains how they can use hardware attestation to verify GrapheneOS and permit it. They should also be made aware that the Play Integrity API has no actual security standards and permits devices with no security patches for a decade. They're permitting incredibly insecure devices but not hardened devices with GrapheneOS.
Published at
2024-12-10 19:59:55Event JSON
{
"id": "37d6e44b1bb1b4bfd9dd54c7b1aeb8f8e4744bafeb6fa922d5d7dd402108bddf",
"pubkey": "5468bceeb74ce35cb4173dcc9974bddac9e894a74bf3d44f9ca8b7554605c9ed",
"created_at": 1733860795,
"kind": 1,
"tags": [
[
"p",
"09106a64c26ba476058a6649a0356f89990054733fe52f5c0456a3798a6b02c5",
"wss://relay.mostr.pub"
],
[
"e",
"2a09ac6b151c11a888d34d0298dc91f81f60fd0b96fa308439f8062e3796392d",
"wss://relay.mostr.pub",
"reply"
],
[
"proxy",
"https://grapheneos.social/users/GrapheneOS/statuses/113630301119416306",
"activitypub"
]
],
"content": "nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpqpygx5exzdwj8vpv2vey6qdt03xvsq4rn8ljj7hqy263hnzntqtzsxcuwp2 If they insist on verifying device/OS integrity, then they need to read https://grapheneos.org/articles/attestation-compatibility-guide which explains how they can use hardware attestation to verify GrapheneOS and permit it. They should also be made aware that the Play Integrity API has no actual security standards and permits devices with no security patches for a decade. They're permitting incredibly insecure devices but not hardened devices with GrapheneOS.",
"sig": "796b3aab4e8d4b2fb95ef2837a00ecbe8f38d96261e6a55d1c9a18b6fc8f3dfc4caa8c966ab77e02bd2785d07b4852df1f5083ed132ade2dacb8c10042a22b28"
}