• it_depends_man@lemmy.world
    link
    fedilink
    arrow-up
    17
    ·
    22 hours ago

    First of all,

    I don’t understand where the restrictions are going to lie

    Yes. That’s exactly the question.

    The point of the… excitement around this is exactly the uncertainty. We simply don’t know what the EU or national governments of the EU will do with this.

    The first problem is that the “hardware bound attestation” isn’t just hardware bound, it’s specifically Apple and Android’s attestation and NOT the more open standard. That means the device that can do this thing, whatever it’s going to be “necessary” for, MUST always be an Apple or Google device, with that bit intact. Tbh, I don’t really know how much rooting affects this, but I would be surprised if it didn’t.

    The second problem is that once the infrastructure for blocking access to something and requiring this sort of authentication is in place, it’s just a list of targets. It’s very easy to add another platform, website, app or anything else behind it.

    And the reason for this excitement happening now is that the specification that was given for all this to happen previously only said it should be “secure” somehow, but not detailing the “how”. They think they can do it as an implementation detail and pretend it’s not a big deal. So it’s very clearly something those bastards have tried to be sneaky about.

    Can you use rooted phones

    No, whatever the point of their efforts is, they will make sure to not leave obvious loopholes like that open.