<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: AppAttestationz</title><link>https://news.ycombinator.com/user?id=AppAttestationz</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 08 Apr 2026 12:35:17 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=AppAttestationz" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by AppAttestationz in "German implementation of eIDAS will require an Apple/Google account to function"]]></title><description><![CDATA[
<p>It's a funny comment, because actual malware, very much loves to tamper with the bootloader and OS.<p>Which was the motivation for cryptographically attesting the boot process and OS, and in part paved the way for app attestation.<p>There are alternatives though:
The Android Hardware Attestation API enables attestation on custom ROMs, but the attestation verifier needs a list of hashes for all "acceptable" ROMs. GrapheneOS publishes these but there's nobody, to my knowledge, maintaining a community list.</p>
]]></description><pubDate>Sun, 05 Apr 2026 07:29:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=47647040</link><dc:creator>AppAttestationz</dc:creator><comments>https://news.ycombinator.com/item?id=47647040</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47647040</guid></item><item><title><![CDATA[New comment by AppAttestationz in "German implementation of eIDAS will require an Apple/Google account to function"]]></title><description><![CDATA[
<p>You can bicker about the words all day long. Legitimacy, or perhaps better: authenticity, in this context, would be a bootloader or OS that doesn't allow tampering with the execution of an app.</p>
]]></description><pubDate>Sun, 05 Apr 2026 06:19:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=47646609</link><dc:creator>AppAttestationz</dc:creator><comments>https://news.ycombinator.com/item?id=47646609</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47646609</guid></item><item><title><![CDATA[New comment by AppAttestationz in "German implementation of eIDAS will require an Apple/Google account to function"]]></title><description><![CDATA[
<p>Your whole point is orthogonal to what I said too.<p>I said the title is misleading, which it is.<p>Your argument that app attestation should be avoided because big tech company can withhold it is garbage. It holds no water. They can cut off access to the app in general by removing it from the app stores and the devices that have it installed.<p>American big tech has Europe in a stranglehold, I agree with your sentiment there.<p>eIDAS can be used with the ID reader on Linux even, there's no lock out. They want to offer a convenient alternative for the normies, in a secure manner, I don't mind.<p>Edit: my 70 y/o mother even eIDAS authenticates (not germany, other EU country) on Linux Mint. There's no argument for lockout in my anecdotal perspective.</p>
]]></description><pubDate>Sun, 05 Apr 2026 01:01:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=47645140</link><dc:creator>AppAttestationz</dc:creator><comments>https://news.ycombinator.com/item?id=47645140</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47645140</guid></item><item><title><![CDATA[New comment by AppAttestationz in "German implementation of eIDAS will require an Apple/Google account to function"]]></title><description><![CDATA[
<p>I made an account because I'm qualified to talk about this topic :-) I've spent a considerable time testing every corner case of UX, and DX of an app attested service.<p>App attestation can fail on simulators, Graphene OS, dev builds, I've seen it all. There is one check you can do to see if an app was side loaded, so indirectly, can require Google account.<p>Title is still misleading though, as it explicitly mentions accounts.</p>
]]></description><pubDate>Sun, 05 Apr 2026 00:46:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=47645057</link><dc:creator>AppAttestationz</dc:creator><comments>https://news.ycombinator.com/item?id=47645057</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47645057</guid></item><item><title><![CDATA[New comment by AppAttestationz in "German implementation of eIDAS will require an Apple/Google account to function"]]></title><description><![CDATA[
<p>I agree, there is still a reliance on the tech giants that produce the phones, who are the o'es embedding the cryptographic keys, to make this end to end attestation work.<p>But in pure technical & UX terms, you don't need to be logged in.</p>
]]></description><pubDate>Sun, 05 Apr 2026 00:30:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=47644968</link><dc:creator>AppAttestationz</dc:creator><comments>https://news.ycombinator.com/item?id=47644968</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47644968</guid></item><item><title><![CDATA[New comment by AppAttestationz in "German implementation of eIDAS will require an Apple/Google account to function"]]></title><description><![CDATA[
<p>I spent months designing a system, exactly like this. An account is not needed, at least for Apple.<p>Play Integrity could the worst offender here, as it can be leveraged to force a user to have installed the app through the Play Store. Indirectly, requiring a Google account.</p>
]]></description><pubDate>Sun, 05 Apr 2026 00:26:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47644943</link><dc:creator>AppAttestationz</dc:creator><comments>https://news.ycombinator.com/item?id=47644943</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47644943</guid></item><item><title><![CDATA[New comment by AppAttestationz in "German implementation of eIDAS will require an Apple/Google account to function"]]></title><description><![CDATA[
<p>The title is misleading.<p>App attestation does not require an Apple account nor a google account. For Android, it does limit the ROMs to Google certified ones and requires GMS to be installed if Play Integrity is used. An alternative option, would be to use the Hardware Attestation API directly, GrapheneOS would be thanking you.<p>I've spent a good amount of time implementing exactly this type of system for a backup service.<p>his document specifies a way to cryptographically attest the integrity of a HTTP request hitting a server.<p>The attestation proves the request came from a device and attest the legitimacy of the bootloader, OS and app.<p>Google and Apple are in a privileged position to be able to bypass the app attestation though, so depending on the threat model, it's not bulletproof.<p>edit: Play Integrity could the worst offender here, as it can be leveraged to force a user to have installed the app through the Play Store. Indirectly, requiring a Google account.</p>
]]></description><pubDate>Sun, 05 Apr 2026 00:19:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=47644905</link><dc:creator>AppAttestationz</dc:creator><comments>https://news.ycombinator.com/item?id=47644905</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47644905</guid></item></channel></rss>