| ▲ | lxgr 11 hours ago | |||||||||||||||||||||||||
Only if you need to have the entire application behavior (or at least some trusted confirmation) attested, right? Otherwise, an external USB dongle, tapping a contactless smartcard on a phone etc. could do just fine. | ||||||||||||||||||||||||||
| ▲ | matthewdgreen 11 hours ago | parent [-] | |||||||||||||||||||||||||
Sure, but then you need to receive an attestation from that external dongle, and/or pre-provision it with an identity (like a national ID smartcard.) It might work in places that distribute this hardware, but it's a crummy UX. I expect that the goal of these systems is to make ID verification a requirement for most routine device usage, sadly, and external dongles will crap that up from a UX perspective. There is also the problem that most external hardware is less secure than things like Apple's SEP. (But on the other hand, probably more secure than the long tail of cheap Android phones, which use virtualization rather than real hardware.) | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||