HNHacker News
TopNewBestAskShowJobs

AppAttestationz

26 karma · joined April 5, 2026

submissionscomments
AppAttestationz··on A misalignment of AI in mathematics
Any proof for or against a mathematical conjecture, bruteforced by AI can be the spark for new insights. I'll concede that to the AI companies.

But I agree with the sentiment that the marketing behind these "discoveries" is disingenious. They pretend they solved the problem, but it still takes a bunch of humans to reduce the solution to a simplified and sensible explanation.

AppAttestationz··on Ask HN: Whats your SWE career plan B?
If you ever start making videos, definitely drop your link below, I love watching repairs videos
AppAttestationz··on Ask HN: Whats your SWE career plan B?
Those sound pretty cool! I guess for bike rentals the location is everything though. Surf shop seems chill, I dont know how to surf at all, but I can see myself in onz of those shops too :) I'm not sure how you break into being an electrician, I've dipped my those by wiring up the house I'm building. I guess you need to get certified first though, if you're working for others, depending on the laws of the country you are residing in. Electronic repairs are fun but getting boardviews for boards is a pain in the ass, a lot of manufacturers do not want to give it out...
AppAttestationz··on Ask HN: Whats your SWE career plan B?
Wbu?
AppAttestationz··on Ask HN: Whats your SWE career plan B?
I got fired, so I've been enjoying my other hobbies. :)

1. Electronics repairs (Soldering, replacing caps, mosfets etc, lots of fun debugging things) 2. Old timer car repairs (love working on Volkswagen and Saabs) 3. Electrician (hate the dust, but love drawing plans, cabling, home automation) 4. CNC shop: rebuild parts, 3D CAD work etc

AppAttestationz··on I think the military commissary's freezers were hacked
I'm waiting for the OpenAI report that their agents defrosted everything.
AppAttestationz··on Ask HN: Why are onionv3 services not more popular?
Isn't v2 completely deprecated?

Or are you asking why arent more people using Tor in general?

Domain names are random, cant memorize them. Solving that requires centralization or blockchain of some sorts.

AppAttestationz··on EuroHPC Launches 6 Quantum Calls with €119M in Funding
"This is what happened to the EU with battery technology, renewable technology, AI, digital services, and semiconductors."

I don't agree with the "semiconductor" take of that. ASML, a European company funded by a lot of private and non-European capital, is basically producing the machines that are making all of the high-end semi conductors of the past few years. They have received grants from the EU, arguably small in compared to the private funding though.

IMEC, and their NanoIC research on the other hand receives a lot of funding from the EU.

AppAttestationz··on Nashville uses eminent domain to block data center near zoo
1. A concern is not invalid merely because something else is worse. 2. Leaping to influence by foreign state is non sequitur. What evidence have you observed for that? How do I know you haven't been sent by the corporate tech elites? 3. Focussing on water strawmans the other arguments against data center imho.

I tend to agree with your sentiment, I think datacenters are getting more shit than they deserve, but there are better arguments to be made.

With patience, love and a bit of humor. X

AppAttestationz··on Roblox Officially Supports GrapheneOS
Truth be told, GrapheneOS is the only third party ROM that bothers to make app attestation work.
AppAttestationz··on Opaque, Interoperable Passkey Records (and a Go API)
Wondering how webauthn extensions will fit into this.

PRF for example, takes salts as inputs, if extensions are taken into consideration then it would need to capture input & client extension results too.

AppAttestationz··on Bun's experimental Rust rewrite hits 99.8% test compatibility on Linux x64 glibc
With the amount of changes they've made to WebKit, I honestly don't think we can claim it's just JSC..

https://github.com/oven-sh/WebKit/commits/main/

AppAttestationz··on Hardware Attestation as Monopoly Enabler
I agree with Graphene's take here.

I've defended app attestation against baseless criticism, but this is a valid take.

The only nuance I would make is that hardware attestation as a technology isn't inherently anti-competitive but rather the way these companies implement it.

I would love to see a non-profit attestation service that publishes a list of allowed OS's, and roots that are deemed secure based on reality.

AppAttestationz··on Bun's experimental Rust rewrite hits 99.8% test compatibility on Linux x64 glibc
I suspect that the test suite isn't that great tho. Bun has so many different behaviors compared to other JS engines, sometimes just plain wrong or contradicting the spec. Test suite didnt catch those.. Not sure how much I trust the rewrite :)
AppAttestationz··on Show HN: Building a web server in assembly to give my life (a lack of) meaning
I suspect that the test suite isn't great. Bun has so many different behaviors compared to other JS engines, sometimes just plain wrong or contradicting the spec. Test suite didnt catch those..
AppAttestationz··on Trademark violation: Fake Notepad++ for Mac
Notepad+++ was born.
AppAttestationz··on German implementation of eIDAS will require an Apple/Google account to function
It's a funny comment, because actual malware, very much loves to tamper with the bootloader and OS.

Which was the motivation for cryptographically attesting the boot process and OS, and in part paved the way for app attestation.

There are alternatives though: The Android Hardware Attestation API enables attestation on custom ROMs, but the attestation verifier needs a list of hashes for all "acceptable" ROMs. GrapheneOS publishes these but there's nobody, to my knowledge, maintaining a community list.

AppAttestationz··on German implementation of eIDAS will require an Apple/Google account to function
You can bicker about the words all day long. Legitimacy, or perhaps better: authenticity, in this context, would be a bootloader or OS that doesn't allow tampering with the execution of an app.
AppAttestationz··on German implementation of eIDAS will require an Apple/Google account to function
Your whole point is orthogonal to what I said too.

I said the title is misleading, which it is.

Your argument that app attestation should be avoided because big tech company can withhold it is garbage. It holds no water. They can cut off access to the app in general by removing it from the app stores and the devices that have it installed.

American big tech has Europe in a stranglehold, I agree with your sentiment there.

eIDAS can be used with the ID reader on Linux even, there's no lock out. They want to offer a convenient alternative for the normies, in a secure manner, I don't mind.

Edit: my 70 y/o mother even eIDAS authenticates (not germany, other EU country) on Linux Mint. There's no argument for lockout in my anecdotal perspective.

AppAttestationz··on German implementation of eIDAS will require an Apple/Google account to function
I made an account because I'm qualified to talk about this topic :-) I've spent a considerable time testing every corner case of UX, and DX of an app attested service.

App attestation can fail on simulators, Graphene OS, dev builds, I've seen it all. There is one check you can do to see if an app was side loaded, so indirectly, can require Google account.

Title is still misleading though, as it explicitly mentions accounts.

AppAttestationz··on German implementation of eIDAS will require an Apple/Google account to function
I agree, there is still a reliance on the tech giants that produce the phones, who are the o'es embedding the cryptographic keys, to make this end to end attestation work.

But in pure technical & UX terms, you don't need to be logged in.

AppAttestationz··on German implementation of eIDAS will require an Apple/Google account to function
I spent months designing a system, exactly like this. An account is not needed, at least for Apple.

Play Integrity could the worst offender here, as it can be leveraged to force a user to have installed the app through the Play Store. Indirectly, requiring a Google account.

AppAttestationz··on German implementation of eIDAS will require an Apple/Google account to function
The title is misleading.

App attestation does not require an Apple account nor a google account. For Android, it does limit the ROMs to Google certified ones and requires GMS to be installed if Play Integrity is used. An alternative option, would be to use the Hardware Attestation API directly, GrapheneOS would be thanking you.

I've spent a good amount of time implementing exactly this type of system for a backup service.

his document specifies a way to cryptographically attest the integrity of a HTTP request hitting a server.

The attestation proves the request came from a device and attest the legitimacy of the bootloader, OS and app.

Google and Apple are in a privileged position to be able to bypass the app attestation though, so depending on the threat model, it's not bulletproof.

edit: Play Integrity could the worst offender here, as it can be leveraged to force a user to have installed the app through the Play Store. Indirectly, requiring a Google account.