this post was submitted on 14 Jan 2025
270 points (98.2% liked)

Technology

60456 readers
3951 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Zak@lemmy.world 46 points 11 hours ago (1 children)

Locked in the technical sense of being able to verify the operating system isn't a bad thing. The problem is when the device owner can't add signing keys of their choice.

The latter is what GrapheneOS does.

[–] Corngood@lemmy.ml 15 points 9 hours ago (1 children)

Something that worries me about that is attestation. This is the advice from the GrapheneOS Devs:

https://grapheneos.org/articles/attestation-compatibility-guide

They're asking app developers to trust their keys specifically, which would mean that the app might work on GrapheneOS, but not my fork of GrapheneOS with some cherry picked fix I want.

It would be much better if we stamped this out now, before all online services require attestation.

[–] Zak@lemmy.world 5 points 7 hours ago

Agreed. Microsoft proposed something along those lines under the name "Palladium" a couple decades ago and was widely criticized, even in the mainstream press. Apple and Google doing the same thing to our phones barely got a whimper.