Post B4OxviHPYgDSX0tN44 by GrapheneOS@grapheneos.social
 (DIR) More posts by GrapheneOS@grapheneos.social
 (DIR) Post #B4NqLMMGgwDxHRvEiO by GrapheneOS@grapheneos.social
       2 likes, 2 repeats
       
       @vollaficationist @volla Unified Attestation is the direct opposite of keeping Android open. It's an anti-competitive centralized system putting Volla and other companies selling devices working with them in control of which devices and operating systems people are allowed to use. It's the direct opposite of open. There's nothing neutral or fair about companies approving using their products while disallowing others. Unified Attestation needs to be stopped.https://grapheneos.social/@GrapheneOS/116239523775374959RT: https://grapheneos.social/users/GrapheneOS/statuses/116239523775374959
       
 (DIR) Post #B4O5fPa3v1OENYOTVA by vollaficationist@mastodon.social
       0 likes, 0 repeats
       
       @GrapheneOS Which companies are "disallowed" to partake in #UnifiedAttestation? You have formally and informally been cordially invited. As are any and all other OS manufacturers. Please, let's ease the tone. What about a constructive talk? I believe we should support one another wherever possible and meaningful. Considering the vast market potential, we have all much to gain. Some will choose GOS, some VOS, etc. It's a big cake. Let's ditch Google - unified. Good day!
       
 (DIR) Post #B4O5fPnt5cRt4QrW3E by GrapheneOS@grapheneos.social
       1 likes, 1 repeats
       
       @vollaficationist Unified Attestation includes multiple companies hostile towards GrapheneOS. They've spent years misleading people about GrapheneOS and making attacks on our team. Unified Attestation gives them veto power over app compatibility on GrapheneOS. It puts them in a position where they can harm GrapheneOS with unreasonable requirements and disingenuous concerns to reduce app compatibility. It's also clearly an illegal anti-competitive cartel and participating wouldn't be legal.
       
 (DIR) Post #B4O5fQnZOHmy9jimC8 by GrapheneOS@grapheneos.social
       1 likes, 1 repeats
       
       @vollaficationist Unified Attestation is nothing more than an anti-competitive power grab via a centralized service sitting on top of Android hardware attestation. There has yet to be any valid explanation for why this has been created. It would be entirely possible to have neutral organizations certifying devices and publishing those certificates as signed data usable with Android hardware attestation. There's no valid reason to have a centralized service under the control of these companies.
       
 (DIR) Post #B4O5fRpNZ2pXLdZjea by GrapheneOS@grapheneos.social
       1 likes, 0 repeats
       
       @vollaficationist Volla and the other companies involved in Unified Attestation are anything but neutral. They're selling products and are in no position to fairly evaluate devices for security or to come up with those requirements. These companies should not be the ones choosing requirements and determining which devices and operating systems meet those requirements. Forming a cartel with other companies to lock out everyone else isn't legal. We won't be participating and it WILL be stopped.
       
 (DIR) Post #B4O5hL0PtoB8lkdhbM by howtophil@mastodon.social
       1 likes, 0 repeats
       
       @GrapheneOS @vollaficationist There's no reason to stop people from running Android on "non-certified" devices at all
       
 (DIR) Post #B4O5ktYNuK4OmoDw5g by vollaficationist@mastodon.social
       1 likes, 0 repeats
       
       @GrapheneOS This is currently being discussed. Nothing is written in stone. One way is to have an independent third-party highly renowned institution do test and certification. Please consider that UA is still very much "under construction." Please also note that we respect GOS' work, which is why we reached out to you half a year ago.
       
 (DIR) Post #B4O5lh51lkIQOEsCH2 by GrapheneOS@grapheneos.social
       0 likes, 0 repeats
       
       @vollaficationist GrapheneOS won't participate in any system which requires us to delay our releases while waiting for certification. That's inherently anti-security and is completely unacceptable. We also won't give any companies or organizations veto power over app compatibility on GrapheneOS. It's a horrible idea and we're not going to let it happen. We won't participate and we'll file a lawsuit over the fact GrapheneOS is being banned by companies selling products threatened by GrapheneOS.
       
 (DIR) Post #B4O5lhNSfD2dJPUv0S by GrapheneOS@grapheneos.social
       1 likes, 1 repeats
       
       @vollaficationist The EU has been passing laws working towards banning end-to-end encryption and secure devices. It's completely unacceptable to have an EU-based system controlling which hardware and software is allowed to be used. GrapheneOS is not going to participate in bringing about our own downfall through helping to build or legitimize a system which could be used by EU governments to ban GrapheneOS. Play Integrity API should be banned rather than giving it legitimacy making another one.
       
 (DIR) Post #B4O5lkJJl4VePQa9Sq by GrapheneOS@grapheneos.social
       1 likes, 0 repeats
       
       @vollaficationist Android hardware attestation can already be used to permit arbitrary roots of trust and arbitrary operating systems. There's no need for a centralized system based in Europe built on top of it.It would be better if root-based attestation didn't exist because it's fundamentally insecure for anything serious and primarily useful for anti-competitive and authoritarian purposes. Pinning-based attestation is what's useful for protecting users rather than controlling people.
       
 (DIR) Post #B4O5llEOKsABGRHjQO by GrapheneOS@grapheneos.social
       1 likes, 0 repeats
       
       @vollaficationist We've been actively fighting against the Play Integrity API for years and now. Unified Attestation is another anti-competitive system very similar to it. We're absolutely going to fight against it as much as we have been against the Play Integrity API. Android hardware attestation is an issue itself due to being primarily designed around root-based attestation. We convinced them to add proper pinning-based verification support to make it a real security feature for our usage.
       
 (DIR) Post #B4O5lmFqWwvAREyPKa by GrapheneOS@grapheneos.social
       1 likes, 1 repeats
       
       @vollaficationist In Operation Trojan Shield, a bunch of European states worked with the FBI to sell backdoored devices to organized crime. They marketed these devices as being based on GrapheneOS or as running GrapheneOS. They harmed the reputation of GrapheneOS by marketing it to criminals and put us at high risk of physical harm by violent criminals. More recently, multiple European states are attacking actual GrapheneOS falsely claiming it's mainly used by criminals.https://darknetdiaries.com/episode/146/
       
 (DIR) Post #B4O5lnFWpcGFWXpfTU by GrapheneOS@grapheneos.social
       1 likes, 0 repeats
       
       @vollaficationist Europe passed Chat Control and it's clear many of the countries involved are going to be pushing additional laws to further crack down on end-to-end encryption and secure devices. France has come out as by far the strongest opponent of privacy technology among European countries and is where both iodé and Murena are based. Why would we want to participate in a system where the EU can ban GrapheneOS if we don't comply with authoritarian laws cracking down on secure devices?
       
 (DIR) Post #B4O5ra6OcrGeUBJwa8 by vollaficationist@mastodon.social
       0 likes, 0 repeats
       
       @GrapheneOS I can not relate to this, unfortunately. I focus on an opensource alternative to googlag. Looking forward. Positively, constructively. Let's say UA becomes a success. Well, GOS is free to do their own thing. As are everyone else.
       
 (DIR) Post #B4O5raN3cuaxJr7FYG by GrapheneOS@grapheneos.social
       1 likes, 0 repeats
       
       @vollaficationist Unified Attestation is working towards eroding people's rights within the European Union and beyond. Play Integrity API is bad enough but at least it can be fought against in Europe by taking advantage of people not wanting a US company in control of which hardware and software they're allowed to use. Unified Attestation is directly undermining our efforts to fight against the Play Integrity API in Europe which were starting to get traction. We now have to focus on UA instead.
       
 (DIR) Post #B4O5tbHjCPbYjWaG6C by YoSoyNelson@mastodon.social
       1 likes, 0 repeats
       
       @GrapheneOS @vollaficationist las practicas de los gobiernos como la coersion y violencia también son usados por los delincuentes... Así que deberían eliminarse también los gobiernos... Los cuchillos y armas de fuego también... Los bates de béisbol también lo usan...y no los han eliminado... La amenaza de daño si no les das un porcentaje muy alto de tu valor es usado por gobiernos y estos no han sido eliminados aun...etc...
       
 (DIR) Post #B4O7l1BniYpkNOqZMW by vollaficationist@mastodon.social
       0 likes, 0 repeats
       
       @skywalker2k17 @GrapheneOS Look, it's not "Volla and Murena." It's an open approach. If you have a better idea, pursue it. UA invites any and all. Please understand that the crux of the matter is to achieve app compatibility outside of googlag.
       
 (DIR) Post #B4O7l1KJCvdgnmpMci by GrapheneOS@grapheneos.social
       0 likes, 0 repeats
       
       @vollaficationist @skywalker2k17 It's not an open approach but rather an anti-competitive cartel formed between multiple companies to permit their products while locking out others. GrapheneOS won't participate and we'll file a lawsuit against each company involved for banning GrapheneOS. Unified Attestation is nothing short of a declaration of war on not only GrapheneOS but anyone who wants to be able to choose their hardware and software without needing approval from the EU and EU companies.
       
 (DIR) Post #B4O7l1SSicA3D4dsKe by vollaficationist@mastodon.social
       0 likes, 0 repeats
       
       @GrapheneOS @skywalker2k17 you keep repeating your magical words, my friend. It won't change a thing. Time was much better spent with a constructive dialogue set to solve problems pragmatically. Perhaps Canadian laws could be the problem? 🤔 Just one example of thinking.
       
 (DIR) Post #B4O7l1cO7i6JhrHnns by GrapheneOS@grapheneos.social
       1 likes, 0 repeats
       
       @vollaficationist @skywalker2k17 We're explaining to people what you're actually doing and how it's going to harm them to have an EU consortium of companies in control of which hardware and software they're allowed to use. It's absolutely going to change things. People aren't yet widely aware of how you're declaring war on their freedom to use alternatives including GrapheneOS. Both Canada and the EU forbid companies getting together to make a system allowing their products but not others.
       
 (DIR) Post #B4O7l1o5QDSUI8l92O by Phobos1641@mstdn.jp
       0 likes, 0 repeats
       
       @GrapheneOS @vollaficationist @skywalker2k17 Very insightful and productive arguments you're having there.Shall we schedule a time for the upcoming season finale or...? Oh, but please do not spoil the ending for us spectators--limit the damage, as to say.Please do remember to RSVP.Thanks,Lysander
       
 (DIR) Post #B4O7l1zmiioesQEUGu by vollaficationist@mastodon.social
       0 likes, 0 repeats
       
       @Phobos1641 @GrapheneOS @skywalker2k17 tried, but failed
       
 (DIR) Post #B4O7l29i7okvNCsPk8 by Phobos1641@mstdn.jp
       0 likes, 0 repeats
       
       @vollaficationist @GrapheneOS @skywalker2k17 Eh, you win some, you lose some. 😆
       
 (DIR) Post #B4O7l2OxD8wu8U0aVE by Phobos1641@mstdn.jp
       0 likes, 0 repeats
       
       @skywalker2k17 @vollaficationist @GrapheneOS I'm guessing that's some kind of jab at me for...I don't quite know.Look, I'm all for privacy and all that nice stuff. I like the goal of GrapheneOS. If I wasn't such a poor bastard I'd buy myself a Pixel and use it.I take life in stride. I meant no offense to either party here. If it came across as such...well, I'm sorry.Chill. Have a beer and relax. The universe doesn't care for our petty squabbles. :nyanparrot:
       
 (DIR) Post #B4O7l2vZFt2LldGdKy by Phobos1641@mstdn.jp
       1 likes, 0 repeats
       
       @skywalker2k17 @vollaficationist @GrapheneOS Any one party being in control over what one can do with their own device is a bad thing--that I very much agree with.I am not a fan of Google, nor the European Union, specifically for their attempts at creating (what I consider to be, or damn near be) a surveillance state.I truly hope we see less Google, and less control over what we can do on the Internet. Though I must say, it's quite hard to keep a positive outlook these days I feel like.
       
 (DIR) Post #B4OxS04yodmv32uQxE by vollaficationist@mastodon.social
       0 likes, 0 repeats
       
       @GrapheneOS Will you really? And you didn't Google? Now I'm actually really getting worried about the status of GOS. Well, I wish you the best.
       
 (DIR) Post #B4OxS0JVwbPjm7i2bo by GrapheneOS@grapheneos.social
       0 likes, 0 repeats
       
       @vollaficationist Yes, we'll file a lawsuit against each company involved in Unified Attestation for the damages done by their anti-competitive cartel to GrapheneOS. It's likely not only going to be us filing this lawsuit. We can work with many other stakeholders interested in stopping creeping authoritarianism in Europe eroding people's right to use whatever hardware and software they want to use. You're working alongside politicians pushing expanded Chat Control. This is perfect for them.
       
 (DIR) Post #B4OxS0Yl1vbiXOqDMu by guilg@piaille.fr
       0 likes, 0 repeats
       
       @GrapheneOS @vollaficationist Funny how you don't answer on the Google-part. Why don't you attack them since they control the whole Android ecosystem, making it a mess to anyone to do things different and are pushing to close it even more. Last time you replied you just said Google has more money for lawyers...
       
 (DIR) Post #B4OxS0k6LkgJ6a9H3A by vollaficationist@mastodon.social
       0 likes, 0 repeats
       
       @guilg @GrapheneOS I suspect GOS is more, or different, from what they state they are. And from where do we always see v projection?
       
 (DIR) Post #B4OxS3F13mbAr2czVw by GrapheneOS@grapheneos.social
       0 likes, 0 repeats
       
       @guilg @vollaficationist We've been actively fighting against the Play Integrity API for years. We were making substantial progress in both Europe and India. We've also been coordinating with multiple other companies towards filing a lawsuit against Google. Unified Attestation is an enormous gift to Google helping to legitimize what they're doing with the Play Integrity API. Volla is playing into the hands of authoritarians who want systems disallowing people using arbitrary hardware/software.
       
 (DIR) Post #B4OxS3XnvvcxnJPznc by celeduc@mastodon.social
       0 likes, 0 repeats
       
       @GrapheneOS @guilg @vollaficationist it's an ugly deal that the @EUCommission has made with the tech giants in exchange for #ChatControl and #DigitalOmnibus
       
 (DIR) Post #B4OxS3kDBnYIPnDu8e by vollaficationist@mastodon.social
       0 likes, 0 repeats
       
       @celeduc @GrapheneOS @guilg @EUCommission Volla develops not only devices or OS, or AI and more. It's also developing a new ecosystem as well as an infrastructure. Full decoupling. A fully, autonomous communications system. GOS is a hundred thousand miles from this, right. They do googlag-ware and now even Moto, lol.
       
 (DIR) Post #B4OxS3xKP22n4TMNaC by GrapheneOS@grapheneos.social
       0 likes, 0 repeats
       
       @vollaficationist @celeduc @guilg @EUCommission Volla sells white labelled devices from an ODM. Your devices don't come close to the security of an iPhone or Pixel. You're making extraordinarily inaccurate attacks on the GrapheneOS project. We're absolutely working on building alternatives to the functionality provided by Google Play and much more. We're actively collaborating with other projects sharing the same goals and approach we have. Volla does not share our goals or approach.
       
 (DIR) Post #B4OxS45ptOqjUrLAqO by vollaficationist@mastodon.social
       0 likes, 0 repeats
       
       @GrapheneOS @celeduc @guilg @EUCommission my dear friend, you did googlag-ware, and now Moto. It's quite amusing just how vigorously you defend American BigTech. Now disclose who is funding this social media frenzy.
       
 (DIR) Post #B4OxS4ViLBY8n7RqBE by vollaficationist@mastodon.social
       0 likes, 0 repeats
       
       @GrapheneOS @celeduc @guilg @EUCommission I hoped you'd come to this. GOOGLAG is better, right?!? And iPhone... Well, I rest my case. Perhaps you are not who you claim to be? Sure, you're registered in Canada. Registered.
       
 (DIR) Post #B4OxS4orC0rVkUP81A by vollaficationist@mastodon.social
       0 likes, 0 repeats
       
       @skywalker2k17 @Phobos1641 @GrapheneOS but who is this dude, or many dudes, being kind of omnipresent (look it up) all over social media, 24/7¿ For me, today was my first day. A little shocked.Whatever, UA is open to anyone. And this fact is why the GOS dude is alleging, empty handed, that is illegal in Canada and EU. According to him/her it's probably globally illegal to contest googlag, right. You're welcome.
       
 (DIR) Post #B4OxuaRbColxwL7WE4 by danieldk@mastodon.social
       0 likes, 0 repeats
       
       @vollaficationist @celeduc @GrapheneOS @guilg @EUCommission And the Volla Phone Quintus is the Daria Bond 5G from an Emirates company (marked up by 560 Euro). Given that Eurowashing, maybe attacking GrapheneOS for using Pixel hardware is a bit rich? At least Pixel has proper device security.Back to to the original topic. I only have a stake in this as an EU citizen, but having a small set of companies decide who can run what is bad, it's another attack on the freedom of EU citizens.
       
 (DIR) Post #B4OxuakO4xnksbuWVk by khw@digitalcourage.social
       0 likes, 0 repeats
       
       @danieldkI would agree to the lower paragraph and add the following thought:Maybe it would be wise to not let the only companies with privacy in the mind get divided. Arguments ad hominem are not very convincing.@vollaficationist @celeduc @GrapheneOS @guilg @EUCommission @GrapheneOS
       
 (DIR) Post #B4OxuaxrGsZpYODHVY by danieldk@mastodon.social
       1 likes, 0 repeats
       
       @khw @vollaficationist @celeduc @GrapheneOS @guilg @EUCommission Centralized remote attestation is diametrically opposed to privacy, since it makes projects vulnerable to pressure to weaken security & privacy, delay updates, etc.AFAIK the support for remote attestation that is already provided in AOSP does not suffer from this issue, because there is not a single entity that enforces it (banks can whitelist signing key fingerprints).So the only reason I can think of is control.
       
 (DIR) Post #B4Oxuc6l1HI16HNu1A by danieldk@mastodon.social
       1 likes, 0 repeats
       
       @khw @vollaficationist @celeduc @GrapheneOS @guilg @EUCommission This is not just a theoretical concern.Some European countries border on autocracy. Imagine that this initiative is successful. An autocrat could pressure Volla et al. to only attest phones that have a chat backdoor under the thread of banning them from the market.It is anti-privacy, anti-security, and anti-freedom.
       
 (DIR) Post #B4OxvgPUVfUUjUenNg by khw@digitalcourage.social
       0 likes, 0 repeats
       
       @danieldkBut that has nothing to do, whatsoever, with the attestation. That said state could pressure volla et al that only phones with backdoor are allowed in the EU.@vollaficationist @celeduc @GrapheneOS @guilg @EUCommission
       
 (DIR) Post #B4Oxvh3C83FYidEVGa by GrapheneOS@grapheneos.social
       0 likes, 0 repeats
       
       @khw @danieldk @vollaficationist @celeduc @guilg @EUCommission It has everything to do with a centralized attestation system. Once this system starts being adopted, the EU can require it for banking/government apps as they began the process of doing with the Play Integrity API. They can then hijack it and begin enforcing their own requirements such including disallowing encryption without backdoors. There should be no organization in charge of which devices and operating systems are allowed.
       
 (DIR) Post #B4OxvhSib9fNznAt3A by khw@digitalcourage.social
       0 likes, 0 repeats
       
       @GrapheneOSBut they, the EU, can do this all along. No matter if there is something like attestation or not.@danieldk @vollaficationist @celeduc @guilg @EUCommission
       
 (DIR) Post #B4OxvhgXlkj2gfdvbE by GrapheneOS@grapheneos.social
       0 likes, 0 repeats
       
       @khw @danieldk @vollaficationist @celeduc @guilg @EUCommission Attestation enables them to enforce it. Otherwise, people can import devices not complying with the rules they place on devices sold within Europe. Banning people from using devices from elsewhere is far more extreme and oppressive so that's a lot less likely. It's also far harder to enforce and if things have gotten that bad then many people are going to be unintentionally breaking oppressive laws regardless.
       
 (DIR) Post #B4OxvhtJ0IvxKFc7UW by GrapheneOS@grapheneos.social
       1 likes, 0 repeats
       
       @khw @danieldk @vollaficationist @celeduc @guilg @EUCommission Being able to take away compatibility with banking and government apps based on a system imposing arbitrary rules with certification required for each release is authoritarian. Regardless of the motivation for building this kind of system, the end result is a powerful tool for a police state. Root-based attestation is inherently anti-competitive and primarily useful for controlling people rather than protecting people.
       
 (DIR) Post #B4OxviHPYgDSX0tN44 by GrapheneOS@grapheneos.social
       0 likes, 0 repeats
       
       @khw @danieldk @vollaficationist @celeduc @guilg @EUCommission If companies insist on permitting only certain devices and operating to be used then the system should be one that's distributed around the world with multiple neutral organizations not tied to the companies making devices or governments. However, delaying updates for certification is inherently anti-security. It would be impossible to quickly ship security patches without breaking compatibility with many important apps.
       
 (DIR) Post #B4Oxvl2HJOtT4wppOS by GrapheneOS@grapheneos.social
       1 likes, 0 repeats
       
       @khw @danieldk @vollaficationist @celeduc @guilg @EUCommission Pinning-based attestation is a useful security feature for protecting users and has little potential for abuse to prevent competition and enforce authoritarian laws. Root-based attestation is what causes those problems. Root-based attestation has poor security since it depends on none of the TEE/SE implementations getting exploited with their keys extracted. Not much of a security feature when any leaked key can be used to bypass it.