home.social

#verifiedboot — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #verifiedboot, aggregated by home.social.

fetched live
  1. Information about #SecureBoot and #VerifiedBoot on #Linux systems from the masters of boot, with plenty of diagrams for clarification -->
    blog.3mdeb.com/2025/2025-07-18
    @3mdeb

    Mobile FOSS-friendly developers could be very helpful by creating a similar explanation about what is "open" and what is "closed," who gets what permissions where, what is proprietary, what is manufacturer controlled and what is owner controlled, etc, and compare #GrapheneOS to #PostMarketOS, #UbuntuTouch, iPhone, and Mobian. @debian

    That someone could be me with enough time and effort since no one else seems to be doing it. But it would be quite the study and a comprehensive explanation would require extensive research. The AOSP (non/semi) closure issue remains unclear to many people.

    Why can't people just have a good Linux phone with full read write permissions and control their own crypto keys as it the case for workstations?
    @postmarketOS

  2. Auditor app version 78 released:

    github.com/GrapheneOS/Auditor/

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/9761-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  3. Auditor app version 77 released:

    github.com/GrapheneOS/Auditor/

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/8830-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  4. Did somebody manage to lock the #Android bootloader with #CustomRom (#LineageOS) using custom Android #VerifiedBoot keys? I am looking for some system to sign update images automatically. I don't like the idea of having the bootloader unlocked all the time.

    I am strict about this. On the laptop I also use secure boot with a signed kernel with my own keys. There hopefully must be a way to do something like this on phones. Right?

  5. Auditor app version 76 released:

    github.com/GrapheneOS/Auditor/

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/8065-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  6. Auditor app version 75 released:

    github.com/GrapheneOS/Auditor/

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/7900-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  7. Auditor app version 74 released:

    github.com/GrapheneOS/Auditor/

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/6368-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  8. Oh, I completely forgot to announce it here, new blogpost!

    This time I talk about Android Verified Boot, and why not supporting it out-of-the-box doesn’t mean that something is inherently insecure.

    tgrush.bearblog.dev/android-ve

    #Android #Security #VerifiedBoot

  9. Auditor app version 73 released: github.com/GrapheneOS/Auditor/.

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/5834-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  10. Auditor app version 72 released: github.com/GrapheneOS/Auditor/.

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/5715-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  11. Auditor app version 71 released: github.com/GrapheneOS/Auditor/.

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/5420-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  12. Auditor app version 70 released: github.com/GrapheneOS/Auditor/.

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/4972-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  13. We currently sign our factory images releases with the signify tool from OpenBSD. It provides tiny signatures that are easy to verify on any distribution with signify in their repositories. This is much less important than in the past because you can verify the completed install.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor #signify #openssh

  14. Auditor app version 69 released: github.com/GrapheneOS/Auditor/.

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/4597-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement #auditor

  15. GrapheneOS requires fs-verity for out-of-band system component updates since our previous release:

    grapheneos.org/releases#202301

    This is part of our ongoing verified boot improvements to fix massive flaws we've discovered in the standard Android verified boot which largely break it.

    #grapheneos #android #security #vulnerability #VerifiedBoot #MeasuredBoot #attestation

  16. Auditor app version 68 released: github.com/GrapheneOS/Auditor/.

    See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

    Forum discussion thread:

    discuss.grapheneos.org/d/3216-

    See attestation.app/about and attestation.app/tutorial for info about the app and optional monitoring service.

    #GrapheneOS #privacy #security #android #attestation #VerifiedBoot #MeasuredBoot #HSM #SecureElement

  17. GrapheneOS continues to work on improving verified boot and hardware attestation security significantly beyond the basic system in standard Android 13.

    As part of this, our app repository client now supports installing fs-verity metadata with packages:

    grapheneos.social/@GrapheneOS/

    #grapheneos #privacy #security #android #verifiedboot #attestation #measuredboot #fsverity #integrity #auditor

  18. Android 13 QPR1 fixed the issues we reported with hardware-based attestation via the secure element for the Pixel 6, Pixel 6 Pro, Pixel 6a, Pixel 7 and Pixel 7 Pro.

    Our Auditor app can now make full use of the bleeding edge hardware-based attestation features on these devices.

    #grapheneos #privacy #security #attestation #hsm #verifiedboot #secureboot #measuredboot #android