• Zak@lemmy.worldOP
    link
    fedilink
    English
    arrow-up
    55
    ·
    20 hours ago

    Locked in the technical sense of being able to verify the operating system isn’t a bad thing. The problem is when the device owner can’t add signing keys of their choice.

    The latter is what GrapheneOS does.

    • Corngood@lemmy.ml
      link
      fedilink
      English
      arrow-up
      21
      ·
      18 hours ago

      Something that worries me about that is attestation. This is the advice from the GrapheneOS Devs:

      https://grapheneos.org/articles/attestation-compatibility-guide

      They’re asking app developers to trust their keys specifically, which would mean that the app might work on GrapheneOS, but not my fork of GrapheneOS with some cherry picked fix I want.

      It would be much better if we stamped this out now, before all online services require attestation.

      • Zak@lemmy.worldOP
        link
        fedilink
        English
        arrow-up
        7
        ·
        17 hours ago

        Agreed. Microsoft proposed something along those lines under the name “Palladium” a couple decades ago and was widely criticized, even in the mainstream press. Apple and Google doing the same thing to our phones barely got a whimper.