← Back to context

Comment by grapheneos

3 days ago

GrapheneOS didn't create any attestation system and has been a very strong advocate against apps disallowing people from using an arbitrary device or OS. For developers insisting on doing it, we explain how to permit other operating systems beyond Google certified ones using the standard Android hardware attestation system. We provide a signed JSON file with our verified boot key fingerprints for use with it. Other operating systems can do the same as long as they preserve the security model including verified boot. It isn't anything added or created by GrapheneOS but rather is fully functional in a properly done release build of the Android Open Source Project signed with release keys.