this post was submitted on 25 Mar 2026
110 points (95.1% liked)
Fediverse
41259 readers
228 users here now
A community to talk about the Fediverse and all it's related services using ActivityPub (Mastodon, Lemmy, Mbin, etc).
If you wanted to get help with moderating your own community then head over to !moderators@lemmy.world!
Rules
- Posts must be on topic.
- Be respectful of others.
- Cite the sources used for graphs and other statistics.
- Follow the general Lemmy.world rules.
Learn more at these websites: Join The Fediverse Wiki, Fediverse.info, Wikipedia Page, The Federation Info (Stats), FediDB (Stats), Sub Rehab (Reddit Migration)
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Isn't checking the bootloader enough?
Not really. If I'm running as root or with a custom firmware, I can easily fake that my phones bootloader is locked, when in fact it isn't.
Attestation creates a "chain of trust", starting at the hardware level. So, an external website can verify that the hardware -> operating system -> application software are all "intact".
"intact" is a very subjective term (which is why many technical people are against it), but that definition of "intact" will be defined by Google, Apple, Microsoft, or (possibly) whatever this EU Governing Body is.
However, it will not be defined by you the device owner.