2026-03-09 17:54:05 UTC
in reply to

npub123…g0ht5 on Nostr: nprofile1q…fzr8z Apps don't use the hardware-based attestation API directly in ...

Apps don't use the hardware-based attestation API directly in practice by rather using a service like the Play Integrity API choosing what's allowed. Unified Attestation is a group which wants to use hardware-based attestation to choose what's allowed themselves. We don't think hardware-based attestation should be used to choose which operating systems are allowed and also don't agree with this specific group we know are selling insecure products adding vendor lock-in for themselves.