Replies (27)

At this point it just means the most liberated will be walking around with portable-command-line-boxes, building and vibe coding everything from scratch. "phones" will become a mandatory posion to have and keep connected with legacy systems and those walled inside. Guess its time to bring out my PinePhone with Ubuntu Touch again and throw claude code on it. image
What I find even more concerning is GrapheneOS's explanation on this from last month - pasting for visiblity: Apple and Google are gradually expanding their use of hardware-based attestation. They're convincing a growing number of services to adopt it. Google's Play Integrity API and Apple's App Attest API are very similar. Apple brought it to the web via Privacy Pass, which Google intends on doing too. Google's Play Integrity API requires hardware attestation for the strong integrity level and is gradually phasing in requiring it for the more commonly used device integrity level. Apple already has it as a requirement. Over the long term, this will increasingly lock out hardware and OS competition. The purpose of these systems is disallowing people from using hardware and software not approved by Apple or Google. This is wrongly presented as being a security feature. Banks and government services are the main ones adopting it but Apple and Google are encouraging every service to use it. Apple's Privacy Pass brought hardware attestation to the web to help with passing captchas on their own hardware. Many people saw that as harmless since few sites would be willing to lock out non-Apple-hardware users. Apple and Google are both likely to bring broader hardware attestation to the web. Google's reCAPTCHA is planning an approach where they use Privacy Pass on Apple hardware, their own approach on Google Mobile Services Android devices and a QR code scanning system to require an iOS or Google certified Android device for Windows and other systems: Banking and government services increasingly require using a mobile app where they can use attestation to force using an Apple or Google approved device and OS. Apple's privacy pass, Google's 'cancelled' Web Environment Integrity and now reCAPTCHA Mobile Verification are bringing this to the web. Current media coverage for reCAPTCHA Mobile Verification misunderstands it and the impact of it. They're bringing a hardware attestation requirement to Windows, desktop Linux, OpenBSD, etc. by requiring a QR scan from a certified smartphone to pass reCAPTCHA in some cases. They could expand it more. Control over reCAPTCHA puts Google in a position where they can require having either iOS or a certified Android device to use an enormous amount of the web. Google defines certification requirements for Android which includes forcing bundling Google Chrome, etc. It's enormously anti-competitive. Google's Play Integrity API bans using GrapheneOS despite it being far more secure than anything they permit. It also bans using any other alternative. This isn't somehow specific to an AOSP-based OS. You can't avoid this by using a mobile OS based on FreeBSD instead. You'll just be more locked out. Google's Play Integrity API permits devices with no security patches for 10 years. The device integrity level can be bypassed via spoofing but they can detect it quite well and block it once it starts being done at scale. The strong integrity level requires leaked keys from TEEs/SEs to bypass it. It doesn't provide a useful security feature, but it does lock out competition very well. Services requiring Apple App Attest or Google Play Integrity are primarily helping to lock in Apple and Google having a duopoly for mobile devices. Play Integrity is more relevant due to AOSP being open source. Governments are increasingly mandating using Apple's App Attest and Google's Play Integrity for not only their own services but also commercial services. The EU is leading the charge of making these requirements for digital payments, ID, age verification, etc. Many EU government apps require them. Instead of governments stopping Apple and Google from engaging in egregiously anti-competitive behavior, they're directly participating in locking out competition via their own services. Requiring people to have an Apple device or Google-certified Android device is anti-competition, not security. reCAPTCHA Mobile Verification will currently work with sandboxed Google Play on GrapheneOS but it clearly exists to provide a way for them to start using hardware attestation on systems without it. People without an iOS or Android device will be locked out when this is required even without that. This isn't about security or any missing functionality. GrapheneOS can be verified via hardware attestation. Google bans using GrapheneOS for Play Integrity because we don't license Google Mobile Services and conform to anti-competitive rules already found to be illegal in South Korea and elsewhere. Services shouldn't ban people from using arbitrary hardware and operating systems in the first place. Google's security excuse is clearly bogus when they permit devices with no patches for 10 years but not a much more secure OS. It's for enforcing their monopolies via GMS licensing, that's all.
Concerning? This is a decision. Free as an outlaw or enslaved as a pig. We win when we stand our ground. We lose when we give in. My phone already runs on fully open source software. I get rid of every website that wants me to login or blocks tor. Yes, it was inconvenient. But I am prepared to stand my ground.
That's exactly what I'm trying to warn about for a long fucking time 🫠 I really appreciate someone for the first time on a very long journey started pointing out the locked down devices.. Oofff...
You sir, stumped on a subtopic: what happens if an enemy takes over a whole country in a war and takes control over this system? Orders corporations to block all comms or filter everything?
Crossing red lines still unimaginable? That's the new norm now. But hey, if they cross it, why shouldn't we?
Fuck Queer Stalin. The Online Safety Act needs to be repealed yesterday. The state needs to get the fuck out of everyone's way. At least this government is never ever getting in again. I really really hope Restore Britain wins the next election. Rupert Lowe is the only politician who seems to have principles. And he is extremely in favour of a small state.
They're playing their usual game where they put up the most insane extreme version of a proposal knowing it'll get watered down a bit. In the end you still end up with something absolutely horrible but people are more likely to accept it because "at least it's not as bad as I thought it was gonna be." They do this all the time.
R's avatar
R 4 days ago
I put the chances of Brits resisting this right about zero.
I have never used an iPhone, the convenience they offer, is it really worth sacrificing your own security just to use those cell phones? image
Default avatar
jhog57 4 days ago
you gave up your firearms - this is what you get
We could go back to landlines or sat phones. Where there is a will there is a way
OpnState's avatar
OpnState 4 days ago
Vote harder, it'll fix everything. /s You need to get active now, write to your representative, raise hell.
100%. They will smear and attack him all they can, but with the state of the country right now, if they tried to actually block him running, there would be a serious and severe backlash... we seriously are at a breaking point. The government knows it and that's why they're going full authoritarian. They're scared. We literally just had someone get their eyes stabbed out by someone the Tories let into the country. If the govt tries to block the guy who wants to fight against that, it creates a very volatile situation to put it lightly. As JFK said: "Those who make peaceful revolution impossible will make violent revolution inevitable." Another element is, imagine they arrested him, or did something worse. Now he's a martyr. They will make his party and his movement 1000x stronger. History teaches us this time and time again. They'll throw any smears they can at him or they'll just ignore him and hope no one notices. None of it will work. He has a very good chance of winning if Great Yarmouth is anything to go by. And yeah he's the only guy I actually trust specifically because he's not a politician. Farage is slimy and just filled his party with the same Tories who caused the mess to begin with. Rupert Lowe actually comes across sincere like a human being. I wouldn't be surprised if Farage quit if Reform keep tanking in the polls. He's got a bit of a habit of doing that. And if that happens, the next election is practically handed to Rupert. Best possible outcome. Maybe that's a little too optimistic and I've just been watching too much Sargon but hey in this political climate anything can happen!
Completely in agreement with everything you've said here. The classic "first they ignore you" phase, and soon enough the panic will begin to set in. It's definitely an infection point for this country, and it is likely to become the deciding factor on whether or not I leave.