upvote
Why would someone want android with crappy apps comparing to linux on the old laptop?
reply
Better sandboxing. If one of the programs you apt-get is hacked through supply chain compromise or something, it has full access to all the goodies in your user profile. There are distros that attempt to implement sandboxing but in those distros your browser can't really be jailed properly. Qubes has tighter isolation than android does, but is slower and too much of a hassle for your typical employee or relative.

Android is pretty slick overall and the user experience is simpler and more familiar to people than Windows or Linux (even if they're an iPhone user). You'd be surprised how many people don't really use PCs.

reply
Would be interesting for x86-based tablets/convertibles, like for instance an old Lenovo X1. I tried using these with Linux with various different distributions, including PostmarketOS, and it was not a good experience.
reply
Running apps that require a phone and are not available for Linux, without putting them on your actual smartphone (if any)
reply
I bet soon most of the apps you can only get on a smartphones are gonna require some kind of attestation that is unlikely to be given to your laptop running an "unsanctioned" version of android.

Though it might have some use if you at least can run linux userland inside android, including a whole desktop session, without any performance degradation.

reply
>I bet soon

With this attitude it's almost inevitable. Politics can stop the corporate-OS attestation apocalypse. If it happens, it's on us.

reply
It is difficult to push back agaisnt banks. My bank started charging for some in site transactions and even some help desk. "We are migrating to online banking"
reply
It was trivial for me to choose a couple of different local credit unions instead of any bank. I don't need any app, but their apps both do work on my rooted lineage phones. Their websites work on my firefox with ublock origin on linux.

A long time ago when I was young and not yet thoughtful I had a variety of regular big name banks like Citi and BofA etc.

It was the easiest thing in the world to just choose a different one that works for me.

reply
Opposing remote attestation in full generality is the wrong place to draw the line IMHO. Too many useful capabilities rely on attestation.

For example, would you really want to live in a world in which photographs are no longer considered evidence of anything because any photo might be AI generated? When a citizen standing on his apartment's balcony used his camcorder to record police beating Rodney King in 1991, it started a national movement against police brutality. So, you're OK with a world where there can be no national conversation sparked by any recording because as far as anyone knows, the recording could've been faked by AI? Remote attestation by the camera is the only way I have been able to think of to avoid that world.

For another example, banking and finance started relying on attestation in 1997 with the availability of the IBM 4758 PCI Cryptographic Coprocessor and have come to rely heavily on it.

reply
How will remote attestation prove that you were actually standing on the balcony pointing the camera, and not recording some slop you generated? The analog hole is a real problem.

Don't worry, photographs were being faked before Lee Harvey Oswald.

reply
The optical data will be cryptographically bound to the state of the autofocus mechanism and to the output of a LiDAR scanner.

We know it is practical to have a LiDAR scanner in the same assembly as an image sensor because the rear camera bump of the iPhone Pro has a LiDAR scanner.

The technology need not be 100% tamper-proof to have a large effect on society: there is a huge difference in persuasiveness between the claim that anyone could have created a particular video by submitting to an AI some starting videos and images and some prompts and the claim that anyone with years of training and experience in cutting-edge microelectronics could have bought 500 iPhones and used very expensive equipment to create 499 ruined iPhones and one iPhone that can be used to create false attestations of recordings -- particularly because in a high profile instance such as a repeat of the Rodney King beating, Apple engineering would tend to be very interested in examining the device used to make the recording.

reply
> We know it is practical to have a LiDAR scanner in the same assembly as an image sensor because the rear camera bump of the iPhone Pro has a LiDAR scanner alongside the optical lenses.

The iPhone Pro starts at $1199.

Moreover, LiDAR is essentially a laser that emits at a particular wavelength and a camera that detects that wavelength, so it could be fooled by pointing it at a screen that emits at the same wavelength, which in turn could be an ordinary screen with something in front of it that converts light at a wavelength it emits to the one the LiDAR sensor is expecting.

And that's if you insist on using light. The LiDAR sensor itself is an analog piece of hardware that converts the light into an electrical signal, so if you substitute its electrical output as the input to the signing hardware then it signs whatever you want and never knows the difference.

The hardest part about this is probably creating a credible depth map of a generated 2D image, which is the part that doesn't require signatures or attestation.

> The technology need not be 100% tamper-proof to affect society: there is a huge difference in persuasiveness between the claim that anyone could have created a particular video by submitting to an AI some starting videos and images and a few prompts and the claim that anyone with years of technical training and experience could have bought 500 iPhones and used very expensive equipment to create 499 ruined iPhones and one iPhone that Apple's engineers have not detected yet that can be used to create falsely attested recordings.

Until one of the people with the capacity to do it sets up a website where anyone can submit an image and have it signed.

Moreover, isn't "most people can't do this but some people still can" actually worse? It's a system for providing undue credibility to the forgeries from the people who can do it.

Without even making most legitimate images more credible, since most phone cameras don't have fancy LiDAR hardware.

reply
>The iPhone Pro starts at $1199

The camcorder used to record the Rodney King beating also probably cost at least $1199. LiDAR will spread to cheaper smartphones if enough consumers start to value it, and many (maybe most) consumers will do if it becomes necessary for the consumer to retain the ability to make recordings that can be used as evidence.

>it could be fooled by pointing it at a screen that emits at the same wavelength

LiDAR emits a pulse, then times how long it takes to get a pulse back, so your exploit got a lot more technically complicated since of course these pulses travel at the speed of light.

>substitute its electrical output as the input to the signing hardware

The LiDAR scanner is part of an integrated circuit (IC) that encrypt the data from the LiDAR scanner. To get at the unencrypted data, you would have to uncap the IC and use a scanning electron microscope or such.

How do I know so much about iPhone hardware? I don't, except I know that Apple is widely believed to be the world's leader in hardware security, so I strongly suspect that every single data path in a recent iPhone is encrypted before it leaves any IC.

>Until one of the people with the capacity to do it sets up a website where anyone can submit an image and have it signed.

The web server behind the site would have to be connected to a compromized iPhone Pro. As soon as Apple becomes aware of the web site, they will disable that iPhone Pro. Specifically, they will be able to determine its ID number (term?) from the attestation, and I'm pretty sure they already have the ability to disable an iPhone by ID number.

>Moreover, isn't "most people can't do this but some people still can" actually worse?

If Apple cares and is willing to expend the necessary engineering resources, then anyone (other the Apple itself) who makes any sort of notable or economically important or culturally important use of their ability to create a false attestation will retain the ability for only a brief time.

The last time a public jailbreak was released for modern iPhone hardware running the actively signed, latest iOS version was in May 2020, which is over six years ago. It is possible that someone will publish a jailbreak in the future, but the lifespan of that jailbreak will probably be only a few days. I expect Apple could exert a level of control over "camera remote attestation" similar to the level of control it has already achieved over which OSes (and which apps) can run on its iPhones. In general, these "technical regimes" are designed to make it easy for the engineering organization to recover from exploits as soon as the organization becomes aware of the exploit.

Again: do you really want photographic evidence to stop being useful in almost every situation (e.g., in court)? If not, then what is your alternative to "technical regimes" reliant on remote attestation similar to the regime I just described?

reply
> LiDAR might spread to all smartphones if its starts to become important to society.

You expect $50 phones to have LiDAR hardware?

> LiDAR emits a pulse, then times how long it takes to get a pulse back, so your exploit got a lot more technically complicated since of course these pulses travel at the speed of light.

That's assuming you're trying to detect the pulse rather than sending back photons with particular timing from when you expect it to come. Notice that you can also try more than once and only publish the image where you got the timing right.

You also have the advantage because you can have something which is directly in front of the sensor but is sending back photons later than that because you're pretending to be something which is further away.

> The LiDAR scanner is part of an integrated circuit (IC) that encrypt the data from the LiDAR scanner. To get at the unencrypted data, you would have to uncap the IC and use a scanning electron microscope or such.

With the right equipment you can affect electrical signals within an IC without disassembling it.

Or you can disassemble it. It doesn't have to be easy when only one person has to do it.

> The web server behind the site would be connected to a compromized iPhone Pro. As soon as Apple becomes aware of the web site, they will disable the iPhone. Specifically, they will be able to determine ID number (term?) of the iPhone from the attestation data, and I'm pretty sure they already have the ability to disable an iPhone by ID number.

So they set up an apparatus where they can put any such a phone, buy them in bulk and resell them immediately after use for the same price they paid. Then most are never detected and even if a few of them are, Apple is only disabling the phone of the innocent third party buyer, likely outside of the return window, and thereby negatively impacting the resale value of their own brand.

Also, your premise was that this would be in every phone and then they're not buying late model iPhones, they're getting e-waste phones with dead batteries or cracked screens by the pallet for ~free to use once on their way to the scrapper.

> The last time a public jailbreak was released for modern iPhone hardware running the actively signed, latest iOS version was in May 2020, which is over six years ago. It is possible that someone will publish a jailbreak in the future, but the lifespan of that jailbreak will probably be only a few days.

You're assuming they publish their methods for Apple to patch instead of setting up the service to sign images without documenting exactly how they do it.

And also that every phone OEM cares to that extent, which they obviously don't.

reply
> I know that Apple is widely believed to be the world's leader in hardware security

That's a pretty rich qualification. "I know" suggests you can prove it, but you have to qualify it with "believed" because you can't. You can't cite anyone that audited Apple's source code, or ask a knowledgeable stakeholder for a credible architectural understanding. You haven't written an exploit, or reverse-engineered one.

It's purely faith. You're making an argument "you know" based on the loyal assumption that Apple's marketing is correct. You could be citing security theater muppets for all you know, but apparently your argument isn't contingent on veracity or transparency.

> Again: do you really want photographic evidence to stop being useful in almost every situation (e.g., in court)?

Yes? Do you really want a purity spiral where people that get abused, subjected to police brutality or sexually assaulted are discredited because they're too poor for a LIDAR camera? I would lobby day and night for this two-tiered evidence system to be reversed because it would force the miscarriage of justice as a marketing gimmeck for iPhone technology. It's not a scalable, holistic, trustworthy, accessible, or safe option for anyone, let alone Americans. There is not a single company in the United States that can implement a system like this protected from domestic or foreign adversaries.

Truly, go fuck yourself if you genuinely think this false dichotomy is the only worthy perspective.

reply
What about actual cameras? I still have to see one with a LiDAR.
reply
There are ways to run Android on Linux much more easily than running Linux on Android.
reply
Familiarity

App consistency

Upstream app availability and release cycle

Security.

reply
Games is one use case. I play the iOS version of Balatro on my Mac.
reply
Much better security. Sandboxing and app isolation actually works on Android.
reply
deleted
reply
I wouldn’t want to run Linux or windows on my phone lol.
reply
That sounds suspiciously like jart...
reply
I'd say quite the opposite. jart has been very focused on specific things. While the contribution mentioned looks more butterflying amongst target.

(@0xcafebabe: ADHD high-five, I've got almost the same target list, except I'm playing with their NPUs)

reply
jart unfortunately seems to have had some kind of a mental breakdown involving a hard rightward religious/political pivot around June according to their latest twitter and github activity. They most recently posted a video of the police breaking down their bedroom door. Very sad to see
reply
Jart had a hard rightward pivot shortly after occupy Wall Street where they were advocating for forming militias and pushing for Eric Schmidt for dictator. Obviously they're tremendously talented but they've always been kooky verging on unwell.
reply
It does sound rather... cosmopolitan.
reply
Looks really promising. Once hardware codecs and camera support arrives it might be useful for old laptops. https://github.com/LineageOS/android_device_mainline_generic...
reply