top | item 46934078

(no title)

bluebarbet | 22 days ago

The snarky tone and sarcasm are not helping your case in this thread.

discuss

order

dijit|22 days ago

The tone matched the engagement I received. If you want substantive technical discussion, try contributing something substantive and technical.

I've explained the same point three different ways now. Not one person has actually demonstrated where the technical argument is wrong, just deflected to TOFU comparisons, philosophical ownership debates, and now tone policing.

If Aachen has an actual technical refutation, I'm all ears. But "read the definition" isn't one, and neither is complaining about snark whilst continuing to avoid the substance.

fc417fc802|21 days ago

> I've explained the same point three different ways now.

But you're demonstrably wrong. The purpose of a PKI is to map keys to identities. There's no CA located across the network that gets queried by the Android boot process. Merely a local store of trusted signing keys. AVB has the same general shape as SecureBoot.

The point of secure boot isn't to involve a third party. It's to prevent tampering and possibly also hardware theft.

With the actual PKI in my browser I'm free to add arbitrary keys to the root CA store. With SecureBoot on my laptop I'm free to add arbitrary signing keys.

The issue has nothing to do with PKI or TOFU or whatever else. It's bootloaders that don't permit enrolling your own keys.