| ▲ | nullc 8 hours ago | |
you don't need asymmetric crypto to make remote attest like this. Google can put a hmac key in each device which it knows and keeps secret. Device can author authenticated messages using it. Of course, only google can verify them-- but it appears that the workflow in this depends on google in any case and if anything that limitation would be more a feature to them than a bug. | ||