this post was submitted on 05 Dec 2024
269 points (96.9% liked)
Technology
60083 readers
4322 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Yeah, I'll just assume that my GrapheneOS install is safe, the checker probably wouldn't work anyway...
I haven't checked, does GrapheneOS do reproducible/deterministic builds so that you could verify that the published release matches your image? The boot attestation should not be able to be circumvented, if you trust Google hardware to do what it says on the tin.
Here are the built-in tools for verifying authenticity, a project to reproduce builds, and a thread where the devs confirm reproducibility and other community members link the above.
TL;DR - Yes.
Thanks, interesting. I have used boot attestation but not yet Auditor. Hope to have some quality time reading up on the documentation in the coming three weeks.
I'm considering running my own build farm for updates, so maybe I'll write up a post about it if I get to it.