• gsv@programming.dev
    link
    fedilink
    English
    arrow-up
    3
    ·
    4 days ago

    Do I get this right? A hand full of OS devs who also sell phones form a group that attests combinations of phones and certified copies of their OSs as secure?
    Sounds like self-verifying the own ecosystem of devices and OSs in a cartel-like consortium. But wasn’t that to be circumvented? Shouldn’t the certifying body be independent of the certified products?

    I am having questions.