GrapheneOS criticizes Apple and Google's expansion of hardware-based attestation and Privacy Pass
By
ChuckMcM
Needed another two minutes in the oven. A half-baked bagel.
Summary
GrapheneOS criticizes Apple and Google for expanding hardware-based attestation systems, noting that both companies are pushing services to adopt APIs like Play Integrity and App Attest. The post highlights concerns about Apple bringing attestation to the web via Privacy Pass, with Google planning to follow suit, which raises privacy and control issues for users.
Key quotes
· 4 pulledApple and Google are gradually expanding their use of hardware-based attestation.
They're convincing a growing number of services to adopt it.
Google's Play Integrity API and Apple's App Attest API are very similar.
Apple brought it to the web via Privacy Pass, which Google intends on doing too.
You might also wanna read
Pentagon Confirms Adversaries Using Commercial Phone Location Data to Target US Troops
The Pentagon was warned for nearly a decade that commercial location data from mobile phones could be exploited by adversaries to track US m
New browser-based side-channel attack uses SSD activity analysis to spy on users
Researchers have discovered a new browser-based side-channel attack that can spy on users by analyzing SSD (Solid State Drive) activity thro
arstechnica.com·1d agoNew FROST technique lets websites track visitors by analyzing SSD activity
A new tracking technique called FROST (fingerprinting remotely using OPFS-based SSD timing) allows websites to spy on visitors by analyzing
Trump Mobile investigates data leak exposing customer names and contact details
A potential security flaw on Trump Mobile's website may have exposed personal information (names, emails, addresses, phone numbers) of thous
Third-party UK Visa Portal exposed 100,000+ applicants' passports and selfies online
A third-party website called UK Visa Portal, which is not affiliated with the U.K. government, has been publicly exposing the passports and
Researchers Demonstrate How Inaudible Audio Commands in Podcasts and Videos Can Hijack AI Voice Assistants
Researchers have demonstrated a new cybersecurity threat where hackers can embed inaudible sounds into podcasts, YouTube videos, or other au
