Also, GrapheneOS supports device attestation (the non-google kind at least), which is still ridiculous as such systems have no benefit to people, only to technofeudalist corporations.
Also, GrapheneOS supports device attestation (the non-google kind at least), which is still ridiculous as such systems have no benefit to people, only to technofeudalist corporations.
GrapheneOS literally has an app that uses attestation and isn't for "technofeudalist corporations".
[1] https://frame.work/products/fingerprint-reader-kit?v=FRANTD0...
You don't actually need biometrics to use key material, that's what (f)TPMs are for. They're not set up to be usable out of the box in any Linux distro I've tried, though.
Read that phrase back and then ask "is this the future of computing that we wanted?"
The likes of passkeys, essentially user-hostile ssh keys that live on your device but aren't accessible by you, would have been an unbelievable dystopia to us in the 90s.
"Linux folks need to implement the full stack"
Nah it's fine thanks, I'd rather opt out of corporate serfdom than compromise my principles.
Stop speaking for Linux.
It is what I want.
If you own a mobile phone it's unavoidable. The physical SIM is a guarded area with secrets you can't know or touch - the secrets it holds prove you paid for access to their network.
If you want to carry a zillion others devices you can't access the innards of that prove something about you then good for you. But don't assume the rest of us think that's a good idea. We no more object to carving out a little bit of firewalled memory for the exclusive use of the bank than we object to the electricity meter in our houses. It's also a locked down piece of equipment we can't modify or touch that lives on our property. Most people are happy to grant that intrusion on their personal space in exchange for having the electrity connected.
It's no different on your phone. In return for your phone protecting its details from you, you no longer have to carry a credit card, or driver's licence, or prove you paid for ads to go away in some app, or access your works VPN. I honestly can't see much difference between carrying a credit card the hides some information from me, or putting the same info in the phone and it hiding the info. Except for having one less device to haul around, of course.
And I'm not trying to be snarky, if that's the only thing, it's solvable right now. Everything else will work.
And concerning "you can't just buy a device and install is" - android and iOS are far more secure than any desktop os, and both pixel/iPhones are far more secure than any computer (or any other phone as well (we'll get the third one next year)). GrapheneOS actually explains "whys" in their hardware support faw section.
Generally maintaining an os is a hard work, so that perhaps explains why there's not many mature offerings.
> GrapheneOS supports device attestation (the non-google kind at least)
they have an app that does GOS to GOS attestation.they also run a remote attestation proxy to a google attestation intermediary (doesn't really accomplish anything).
they unfortunately don't provide you with the option to disable the Android APIs that can be used to get a unique hardware identifier from your device (cryptographic identity burned into the silicon) with some extra steps. APIs such as remote attestation and DRM handshake initiation.
What's stopping you from buying a phone, unlocking the bootloader, and flashing whatever ROM you want?
I have several old Android phones, the newest one is s10e from 2019, decent specs but only supports an abandoned version of UBports, not the current one, and no port for postmarketOS.
This is in practice only true of IBM PC compatibles these days, you really can't install any OS on modern Macs. Maybe you can on (some?) Chomebooks?