I hope they just improve that performance, rather than see this and back out of it entirely and require ID checks.
I hope they just improve that performance, rather than see this and back out of it entirely and require ID checks.
And that's why it's been bypassed already
On the other note, can one attach chrome devtools to any electron application?
Pretty sure it's just a flag somewhere to re-enable.
Not the broken anti-competitive Google play store integrity (which is passing for any handset not patched for the last 8 years but with Google buttplug in it, effectively nullifying assurances from the attestation), but a proper hw attestation.
If you jailbreak an iPhone you can still use store apps and watch movies. You don't think that's just because Apple forgot about it, right? Or because the movie studios are merciful? They definitely aren't. It's because they think it'd be illegal to lock you out over it.
Apple doesn't attestation as part of their DRM (afaik) because it wouldn't be very useful. An iOS jailbreak requires the kind of exploits that would break attestation anyway, so it adds little value.
Movie studios could require strong hardware attestation for playback, but in doing so they would limit the set of compatible devices. They are in fact a little merciful (if only because they care about their bottom line).
> It's because they think it'd be illegal to lock you out over it.
I wish.
> You are mistaken. DRM can work in a variety of ways but that is absolutely one of them.
Of course it can work that way. It's software, you can write whatever you want.
It doesn't though. If you prefer, they have chosen to believe this is what the law says because it's a good argument if some partner asks them to do it.
Similarly you can get banned from the eShop if you jailbreak your Nintendo Switch, but they don't stop you from using physical games. They could do that if they wanted to. Or rather, they could make you have to work around it.
No, you're just wrong.
> It doesn't though
It does on Android. hardware-backed safetynet attestation can be required, as a mater of policy. Many things do not require it though, for aforementioned reasons.
See https://developer.android.com/google/play/integrity/verdicts...
"MEETS_DEVICE_INTEGRITY: The app is running on a genuine Play Protect certified Android-powered device. On Android 13 and higher, there is hardware-backed proof that the device bootloader is locked and the loaded Android OS is a certified device manufacturer image."
> you can get banned from the eShop if you jailbreak your Nintendo Switch
Nintendo bans for a bunch of things, but the act of jailbreaking alone is not one of them. They are known to ban you from online services if they detect you cheating in online multiplayer, or if their telemetry detects game piracy.
If they locked you out of playing legitimate physical games for the act of jailbreaking, that would probably be illegal in a lot of jurisdictions. It would also be strategically silly, because a jailbroken console could just pirate the games anyway.
We want a broken and easily bypassable system that only exists to make do-gooders think they did good.
Some of the age verification systems that use digital ids (mDLs) do the same thing but people freak out about how they work because I think they misunderstand the tech.
They system basically asks the mDL via an api call "is this user above the age of 18/21" and the app only responds with a yes or no. It doesn't pass the users fulls details over or anything like that.
As in, if I repeatedly ask for age verification to the same service, does it know:
1) the identity of the user making the request, and 2) whether repeated requests comes from the same user (even if they don't know who it is?)
The age verification bills in the US at least also make it illegal to record that information, sometimes with high penalties (e.g. my reading of Texas's is that it is up to $10k per retained record).
There's a bunch of ways to achieve this privately. The work of Jan Camenisch on Anonymous Credentials and other things was done quite a long time ago now. It's a well studied field.
The vendor is https://www.k-id.com in Discord's case
> Identity documents are deleted after a user’s age group is confirmed, and the video selfies used for facial age estimation never leaves their device.