home.social

#attestation — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #attestation, aggregated by home.social.

fetched live
  1. #RicochetRefresh and #Arti build on #Fedora Atomic #OS.
    #rustlang environment is also functional in #rpm #ostree.
    (#immutability over sandboxing if not live?)
    #FreedomOfThePress #Journalism #ComputerScience #Linux @freedomofpress @torproject

    jk, Rotational #HDD and #Rust work together just fine.
    Anomalies and vulns in #QubesOS . . .
    #console #hacking #rpc #Wayland #fastly @rust

    Foreign Sources as attack vector
    dds6qkxpwdeubwucdiaord2xgbbeyd
    also → APT::KashGrow “true”;

    What other flaws might lie in confidential computing core trust mechanisms?
    theregister.com/security/2026/
    @QubesOS @whonix
    #attestation #TLS
    @rfceditor #GOS

    also, in case you didn't know,
    rpm-ostree kargs --append=
    is really great
    and rpm-ostress works over torsocks, atomic just doesn't like systemd so run 'tor' manually

    #Karg #Kernel

  2. In short: #degoogle wants up-to-date reliable #biometric #data #attestation for yours truly in addition to all the rest if possible.
    No, tnx!

    Google Adds Selfie Video As a Log-In Option - Slashdot

    yro.slashdot.org/story/26/07/2

    > An anonymous reader quotes a report from Engadget: You'll now be able to use selfie videos to log into your Google account. It has long been possible to log into Google using your face, via your phone's face unlock or if your passkey login uses biometrics for verification.

  3. Well, it looks like #MobilePay reverted to check Play Integrity again. #Europe does not have a chance at Digital Sovereignty if all Android phones must be #Google #Certified and businesses keep the only option of #Play #Integrity.

    #Unified #Attestation is the alternative for non Google devices (#Jolla, #Volla, #deGoogled Android) but unless this is mandated by @EUCommission, this means all banking and financial services will be monitored, gated and blocked if needed on a whim.

  4. @nitrokey what do you think about github.com/w3c/webauthn/pull/2 (see github.com/wwWallet for context)? Implementing #eudi_wallet using #nitrokey would sound much better than using any proprietary Apple or Android #attestation code. (edit: replaced old PR by current one)

  5. So attezt now contains 3 components.

    - `atteztd` which is an Attestation CA with an inventory API
    - `attezt-agent` that implement device enrollment and an p11-kit agent.
    - `attezt` that is the client for both the agent and the attestation ca. Modelled after step/step-ca

    Everything has an #varlink APIs as well.

    github.com/Foxboron/attezt

    Very much a work in progress and not everything is wired up correctly. Readme also needs a bit more work.

    #TPM #Attestation #Security #security

  6. Does the chrome Endpoint Verification extension do any TPM attestation? Or is it just osquery wrapped in an extension?

    Tried reading the docs but it doesn't really mention how the information is collected.

    #TPM #Attestation #Chrome #security

  7. Totes deployed device-attest-01 with `attezt` to my local infra, and it works!

    #TPM #Attestation #Security

  8. Would writing/maintain a public for-good Linux TPM attestation service be interesting for people?

    Mainly to help people do the attestation part of `device-attest-01` without self-hosting this.

    #TPM #Attestation

  9. Au #travail vous conduisez des engins ou vous avez une habilitation électrique ?
    Voici (en annexe) les documents qui doivent vous être remis par votre médecin du travail depuis le 1er octobre : legifrance.gouv.fr/download/pd

    #travail #CACES #attestation #médecineDuTravail

  10. CSPs MUST allow customer-provided virtual firmware (with a well-documented interface for achieving UEFI variable persistence and ACPI table information) OR publish the sources for their virtual firmware.

    Transparency has value by @drdeeglaze
    deeglaze.github.io/blog/2025/T

    #ConfidentialComputing #Attestation #ReproducibleBuilds

  11. #AMD #Rewards program was interesting with their pvt.sh #remote #attestation. I checked that script out, it's also quite interesting stuff.