"Apple already shipped attestation on the web, and we barely noticed" https://httptoolkit.com/blog/apple-private-access-tokens-attestation/
#apple #webdev #attestation #competition
Tether Attestation Reveals Reserve Increase of $850 Million in Q2, Excess Reserves Reach $3.3 Billion - Tether, the company behind the USDT stablecoin, has published an attestation revea... - https://news.bitcoin.com/tether-attestation-reveals-reserve-increase-of-850-million-in-q2-excess-reserves-reach-3-3-billion/ #treasurybills #paoloardoino #attestation #elsalvador #bdoglobal #bitcoins #uruguay #tether #news
#news #tether #uruguay #bitcoins #bdoglobal #elsalvador #attestation #paoloardoino #treasurybills
@codemonkeymike
tangentially …
Consider that #Apple has shipped http #Attestation on #iOS devices .
And pushed #Congress to require by #law.
Which they’re now pursuing.
No more #rooted #jailbreaking hacked #linux or #FOSS devices or alternate #browsers (Librewolf for desktop, Bromite for #Android, etc)
The #www (#html) will no longer function with anything except “official” devices/browsers,
new law. #EFF
thanks via @eff for the alert on this. or maybe #ACLU idr
#apple #attestation #ios #congress #law #rooted #jailbreaking #linux #foss #browsers #android #www #html #eff #aclu
Implicit in the #UserAgent fiction is a kernel of truth, though: users trust browsers to act in their best interest (in the "fiduciary duty" sense). Violating that trust should be illegal. #GDPR already acts as if that is the case.
The problem is that this leaves an opening for the #attestation cancer to metastasize. Preventing credential stuffing helps users (at least collectively) so it doesn't breach this standard. But the same technology can be used to do all sorts of user hostile shit!
It gets worse as Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web - a gatekeeper that #Google would control and manage of course. This is #Attestation at its worst in the name of internet privacy and user protection. Surely the geniuses at #Alphabet can come up with better. Problem is, they may not want to. This kind of control suits the tech giants and #Apple has already implement their version. https://arstechnica.com/gadgets/2023/07/googles-web-integrity-api-sounds-like-drm-for-the-web/
#google #attestation #alphabet #apple
Apple already shipped attestation on the web, and we barely noticed - Are we prepared to give up control of our devices and browsing just to get rid of Captchas? This trend is bad for users, bad for the web and very bad for competition imo. #Internet #Attestation #Apple #Google https://httptoolkit.com/blog/apple-private-access-tokens-attestation/
#internet #attestation #apple #google
I don't know who needs to hear this, but a simple hmac'd timestamp eliminates the need for #captcha and stops 99.9999% of bots using web forms.
#webenvironmentintegrity #wei #bot #web #attestation
#captcha #webenvironmentintegrity #wei #bot #web #attestation
#Coda: I've never asked people to share or boost my content; it just doesn't feel right to me.
However, this issue is important. "Regular" people need to know about #WebEnvironmentIntegrity, and how it will be used for evil.
Please share this thread if you are concerned with Google et al taking over control of your web experience.
#WEI #attestation #browser #client #privacy #anonymity #advertisement #advertising #ads #AdBlock #AdBlocker #W3C #IETF #Mozilla #Firefox #control #abuse
#Coda #webenvironmentintegrity #Wei #attestation #browser #client #privacy #anonymity #advertisement #advertising #ads #adblock #adblocker #w3c #ietf #mozilla #firefox #control #abuse
Who else is interested in trusted computing for cypherpunks?
https://tech.michaelaltfield.net/2023/02/16/evil-maid-heads-pureboot/
#linux #Coreboot #HEADS #Qubes #Whonix #Fedora #Xen #tor #u2f #FIDO #computers #crypto #PGP #attestation
#crypto #pgp #attestation #Linux #coreboot #Heads #qubes #whonix #fedora #xen #tor #u2f #fido #computers
🔥⏲️ Fudge Sunday "Fuzz Jam June" A look at the growing importance of fuzzing in platform engineering
#fuzzing #fuzztesting #fuzzylogic #fuzzball #fuzzy #platformengineering #platformengineer #toolchains #attestation #softwaresupplychain #softwaresupplychainsecurity #dast #owasp #waf #cncf #aif #artificialintelliegence #machinelearningmodels #cloudinfrastructure #securityautomation #securitybydesign #scanning #defenseindepth #shiftleft #newsletter #newsletters
#fuzzing #fuzztesting #fuzzylogic #fuzzball #fuzzy #platformengineering #platformengineer #toolchains #attestation #softwaresupplychain #softwaresupplychainsecurity #dast #owasp #waf #cncf #aif #artificialintelliegence #machinelearningmodels #cloudinfrastructure #securityautomation #securitybydesign #scanning #defenseindepth #shiftleft #newsletter #newsletters
New episode of Open at Intel is out! We take a deep dive into software #attestation and remote attestation, especially as it relates to software supply chain security and trusted computing. #openSource #security #podcast https://openatintel.podbean.com/e/building-trust-with-attestation/
#attestation #opensource #security #podcast
🔥⏲️ Fudge Sunday "Press Rewind" This week we take at recent updates in software supply chain security that provide an ability to press rewind.
#security #software #supplychain #sbom #attestation #people #processes
#tools #devsecops #secops #platformengineering #devex #developerexperience #securecoding #internetofthings #embeddedsystems #exploits #computing #cloud #iotsecurity #newsletter #newsletters
#security #software #supplychain #sbom #attestation #people #processes #tools #devsecops #secops #platformengineering #devex #developerexperience #securecoding #internetofthings #embeddedsystems #exploits #computing #cloud #iotsecurity #newsletter #newsletters
Auditor app version 69 released: https://github.com/GrapheneOS/Auditor/releases/tag/69.
See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.
Forum discussion thread:
https://discuss.grapheneos.org/d/4597-auditor-app-version-69-released
See https://attestation.app/about and https://attestation.app/tutorial for info about the app and optional monitoring service.
#GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor
#grapheneos #privacy #security #android #attestation #verifiedboot #measuredboot #hsm #secureelement #auditor
GrapheneOS requires fs-verity for out-of-band system component updates since our previous release:
https://grapheneos.org/releases#2023012500
This is part of our ongoing verified boot improvements to fix massive flaws we've discovered in the standard Android verified boot which largely break it.
#grapheneos #android #security #vulnerability #VerifiedBoot #MeasuredBoot #attestation
#grapheneos #android #security #vulnerability #verifiedboot #measuredboot #attestation
Auditor app version 68 released: https://github.com/GrapheneOS/Auditor/releases/tag/68.
See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.
Forum discussion thread:
https://discuss.grapheneos.org/d/3216-auditor-app-version-68-released
See https://attestation.app/about and https://attestation.app/tutorial for info about the app and optional monitoring service.
#GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement
#grapheneos #privacy #security #android #attestation #verifiedboot #measuredboot #hsm #secureelement
GrapheneOS continues to work on improving verified boot and hardware attestation security significantly beyond the basic system in standard Android 13.
As part of this, our app repository client now supports installing fs-verity metadata with packages:
https://grapheneos.social/@GrapheneOS/109746860952845724
#grapheneos #privacy #security #android #verifiedboot #attestation #measuredboot #fsverity #integrity #auditor
#grapheneos #privacy #security #android #verifiedboot #attestation #measuredboot #fsverity #integrity #auditor
Hey academic people, how do you generate PDF attestation based on forms for colloquium or symposium?
#lazyweb #attestation #colloquium
#sdtps They led the me away to the #Sanhedrin, and all the #chief #priests and most of the #Torah #scholars are gathering together.
And there is nobody there who is not trying to find some #evidence; any #evidence at all against the me, in order to have the me #charged and be put to #death, and they were not finding it.
#proof #verification #corroboration #attestation #TIBTM162
#sdtps #sanhedrin #chief #priests #torah #scholars #evidence #charged #death #proof #verification #corroboration #attestation #tibtm162
Android 13 QPR1 fixed the issues we reported with hardware-based attestation via the secure element for the Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7 and Pixel 7 Pro.
Our Auditor app can now make full use of the bleeding edge hardware-based attestation features on these devices.
#grapheneos #privacy #security #attestation #hsm #verifiedboot #secureboot #measuredboot #android
#grapheneos #privacy #security #attestation #hsm #verifiedboot #secureboot #measuredboot #android