Remix.run Logo
uqers 4 hours ago

I'm very surprised Google put in so much effort to implement an approach that is basically the equivalent of client-side verification of passwords. Did no one designing it mention that it could be defeated by any rooted device?

12_throw_away 3 hours ago | parent | next [-]

Actually I think this approach is very forward looking! Attestation is on the cusp of becoming a very powerful technique. We just need to figure out how to build 100% bug-free and 100% secure hardware and software, and then it's gonna work great.

genxy 11 minutes ago | parent [-]

Wait a minute. I think you might have forgotten a /s, I can spot this kinda thing.

akersten 2 hours ago | parent | prev | next [-]

Well, all one has to do is look at the bigger picture of how rooted devices are being shuffled into 3rd rate/totally blocked experiences and the overall direction of things starts to take very clear shape.

At over a decade old, still prescient as ever: https://www.youtube.com/watch?v=HUEvRyemKSg

demibabs 4 hours ago | parent | prev [-]

Not any rooted device, it must be rooted via an exploit. Still pretty bad, though