Any proof for or against a mathematical conjecture, bruteforced by AI can be the spark for new insights. I'll concede that to the AI companies. But I agree with the sentiment that the marketing behind these…
If you ever start making videos, definitely drop your link below, I love watching repairs videos
Those sound pretty cool! I guess for bike rentals the location is everything though. Surf shop seems chill, I dont know how to surf at all, but I can see myself in onz of those shops too :) I'm not sure how you break…
Wbu?
I got fired, so I've been enjoying my other hobbies. :) 1. Electronics repairs (Soldering, replacing caps, mosfets etc, lots of fun debugging things) 2. Old timer car repairs (love working on Volkswagen and Saabs) 3.…
I'm waiting for the OpenAI report that their agents defrosted everything.
Isn't v2 completely deprecated? Or are you asking why arent more people using Tor in general? Domain names are random, cant memorize them. Solving that requires centralization or blockchain of some sorts.
"This is what happened to the EU with battery technology, renewable technology, AI, digital services, and semiconductors." I don't agree with the "semiconductor" take of that. ASML, a European company funded by a lot of…
1. A concern is not invalid merely because something else is worse. 2. Leaping to influence by foreign state is non sequitur. What evidence have you observed for that? How do I know you haven't been sent by the…
Truth be told, GrapheneOS is the only third party ROM that bothers to make app attestation work.
Wondering how webauthn extensions will fit into this. PRF for example, takes salts as inputs, if extensions are taken into consideration then it would need to capture input & client extension results too.
[flagged]
With the amount of changes they've made to WebKit, I honestly don't think we can claim it's just JSC.. https://github.com/oven-sh/WebKit/commits/main/
I agree with Graphene's take here. I've defended app attestation against baseless criticism, but this is a valid take. The only nuance I would make is that hardware attestation as a technology isn't inherently…
I suspect that the test suite isn't that great tho. Bun has so many different behaviors compared to other JS engines, sometimes just plain wrong or contradicting the spec. Test suite didnt catch those.. Not sure how…
I suspect that the test suite isn't great. Bun has so many different behaviors compared to other JS engines, sometimes just plain wrong or contradicting the spec. Test suite didnt catch those..
Notepad+++ was born.
It's a funny comment, because actual malware, very much loves to tamper with the bootloader and OS. Which was the motivation for cryptographically attesting the boot process and OS, and in part paved the way for app…
You can bicker about the words all day long. Legitimacy, or perhaps better: authenticity, in this context, would be a bootloader or OS that doesn't allow tampering with the execution of an app.
Your whole point is orthogonal to what I said too. I said the title is misleading, which it is. Your argument that app attestation should be avoided because big tech company can withhold it is garbage. It holds no…
I made an account because I'm qualified to talk about this topic :-) I've spent a considerable time testing every corner case of UX, and DX of an app attested service. App attestation can fail on simulators, Graphene…
I agree, there is still a reliance on the tech giants that produce the phones, who are the o'es embedding the cryptographic keys, to make this end to end attestation work. But in pure technical & UX terms, you don't…
I spent months designing a system, exactly like this. An account is not needed, at least for Apple. Play Integrity could the worst offender here, as it can be leveraged to force a user to have installed the app through…
The title is misleading. App attestation does not require an Apple account nor a google account. For Android, it does limit the ROMs to Google certified ones and requires GMS to be installed if Play Integrity is used.…
Any proof for or against a mathematical conjecture, bruteforced by AI can be the spark for new insights. I'll concede that to the AI companies. But I agree with the sentiment that the marketing behind these…
If you ever start making videos, definitely drop your link below, I love watching repairs videos
Those sound pretty cool! I guess for bike rentals the location is everything though. Surf shop seems chill, I dont know how to surf at all, but I can see myself in onz of those shops too :) I'm not sure how you break…
Wbu?
I got fired, so I've been enjoying my other hobbies. :) 1. Electronics repairs (Soldering, replacing caps, mosfets etc, lots of fun debugging things) 2. Old timer car repairs (love working on Volkswagen and Saabs) 3.…
I'm waiting for the OpenAI report that their agents defrosted everything.
Isn't v2 completely deprecated? Or are you asking why arent more people using Tor in general? Domain names are random, cant memorize them. Solving that requires centralization or blockchain of some sorts.
"This is what happened to the EU with battery technology, renewable technology, AI, digital services, and semiconductors." I don't agree with the "semiconductor" take of that. ASML, a European company funded by a lot of…
1. A concern is not invalid merely because something else is worse. 2. Leaping to influence by foreign state is non sequitur. What evidence have you observed for that? How do I know you haven't been sent by the…
Truth be told, GrapheneOS is the only third party ROM that bothers to make app attestation work.
Wondering how webauthn extensions will fit into this. PRF for example, takes salts as inputs, if extensions are taken into consideration then it would need to capture input & client extension results too.
[flagged]
With the amount of changes they've made to WebKit, I honestly don't think we can claim it's just JSC.. https://github.com/oven-sh/WebKit/commits/main/
I agree with Graphene's take here. I've defended app attestation against baseless criticism, but this is a valid take. The only nuance I would make is that hardware attestation as a technology isn't inherently…
I suspect that the test suite isn't that great tho. Bun has so many different behaviors compared to other JS engines, sometimes just plain wrong or contradicting the spec. Test suite didnt catch those.. Not sure how…
I suspect that the test suite isn't great. Bun has so many different behaviors compared to other JS engines, sometimes just plain wrong or contradicting the spec. Test suite didnt catch those..
Notepad+++ was born.
It's a funny comment, because actual malware, very much loves to tamper with the bootloader and OS. Which was the motivation for cryptographically attesting the boot process and OS, and in part paved the way for app…
You can bicker about the words all day long. Legitimacy, or perhaps better: authenticity, in this context, would be a bootloader or OS that doesn't allow tampering with the execution of an app.
Your whole point is orthogonal to what I said too. I said the title is misleading, which it is. Your argument that app attestation should be avoided because big tech company can withhold it is garbage. It holds no…
I made an account because I'm qualified to talk about this topic :-) I've spent a considerable time testing every corner case of UX, and DX of an app attested service. App attestation can fail on simulators, Graphene…
I agree, there is still a reliance on the tech giants that produce the phones, who are the o'es embedding the cryptographic keys, to make this end to end attestation work. But in pure technical & UX terms, you don't…
I spent months designing a system, exactly like this. An account is not needed, at least for Apple. Play Integrity could the worst offender here, as it can be leveraged to force a user to have installed the app through…
The title is misleading. App attestation does not require an Apple account nor a google account. For Android, it does limit the ROMs to Google certified ones and requires GMS to be installed if Play Integrity is used.…