▲ 263 ▼ Android 14 blocks all modification of system certificates, even as root (httptoolkit.com) submitted 2 years ago by pimterry@lemmy.world to c/programming@programming.dev 55 comments fedilink hide all child comments
[–] ArbiterXero@lemmy.world 18 points 2 years ago (3 children) Super handy for if a certificate gets out and needs to be revoked. Idiots. permalink fedilink source hideshow 6 child comments replies: [–] mrkite@programming.dev 30 points 2 years ago (2 children) Maybe read the article and not look like an idiot. All they did was move the certificates into a signed package that is updated through Google Play. They can revoke certs even faster now because it doesn't require a system update. permalink fedilink source parent hideshow 4 child comments replies: [–] ArbiterXero@lemmy.world 15 points 2 years ago Cool, so I can’t revoke the certs myself? Still bad. I can’t add my own for testing? Still bad. They manage it via an app that I can’t change at all? Still bad. permalink fedilink source parent [–] Wahots@pawb.social 6 points 2 years ago* (1 child) What if you can't access gplay for various reasons? (Non-stock OS, geographic lockout, etc etc) Are you just straight-up boned when 14 rolls around? Genuinely curious permalink fedilink source parent hideshow 2 child comments replies: [–] 0x2d@lemmy.ml 4 points 2 years ago I hope that on LineageOS that you will still be able to manage your own certificates permalink fedilink source parent [–] sudotstar@kbin.social 11 points 2 years ago IMO this isn't a real "solution" to the problem here, but this article states Android 14 also allows Google to manage device CAs remotely and push updates via Google Play, and goes into detail about how that mechanism is poorly documented publicly and is basically only an option for Google themselves, not any third party device administrators. Google can easily claim that all security concerns are handled by their own management while continuing to deny access to all third parties to actually handle that responsibility themselves if desired. permalink fedilink source parent [–] mathemachristian@lemm.ee 7 points 2 years ago I mean thats what its mainly for? To quickly update CAs without needing to do it as a system update that the vendor needs to vet first permalink fedilink source parent
[–] mrkite@programming.dev 30 points 2 years ago (2 children) Maybe read the article and not look like an idiot. All they did was move the certificates into a signed package that is updated through Google Play. They can revoke certs even faster now because it doesn't require a system update. permalink fedilink source parent hideshow 4 child comments replies: [–] ArbiterXero@lemmy.world 15 points 2 years ago Cool, so I can’t revoke the certs myself? Still bad. I can’t add my own for testing? Still bad. They manage it via an app that I can’t change at all? Still bad. permalink fedilink source parent [–] Wahots@pawb.social 6 points 2 years ago* (1 child) What if you can't access gplay for various reasons? (Non-stock OS, geographic lockout, etc etc) Are you just straight-up boned when 14 rolls around? Genuinely curious permalink fedilink source parent hideshow 2 child comments replies: [–] 0x2d@lemmy.ml 4 points 2 years ago I hope that on LineageOS that you will still be able to manage your own certificates permalink fedilink source parent
[–] ArbiterXero@lemmy.world 15 points 2 years ago Cool, so I can’t revoke the certs myself? Still bad. I can’t add my own for testing? Still bad. They manage it via an app that I can’t change at all? Still bad. permalink fedilink source parent
[–] Wahots@pawb.social 6 points 2 years ago* (1 child) What if you can't access gplay for various reasons? (Non-stock OS, geographic lockout, etc etc) Are you just straight-up boned when 14 rolls around? Genuinely curious permalink fedilink source parent hideshow 2 child comments replies: [–] 0x2d@lemmy.ml 4 points 2 years ago I hope that on LineageOS that you will still be able to manage your own certificates permalink fedilink source parent
[–] 0x2d@lemmy.ml 4 points 2 years ago I hope that on LineageOS that you will still be able to manage your own certificates permalink fedilink source parent
[–] sudotstar@kbin.social 11 points 2 years ago IMO this isn't a real "solution" to the problem here, but this article states Android 14 also allows Google to manage device CAs remotely and push updates via Google Play, and goes into detail about how that mechanism is poorly documented publicly and is basically only an option for Google themselves, not any third party device administrators. Google can easily claim that all security concerns are handled by their own management while continuing to deny access to all third parties to actually handle that responsibility themselves if desired. permalink fedilink source parent
[–] mathemachristian@lemm.ee 7 points 2 years ago I mean thats what its mainly for? To quickly update CAs without needing to do it as a system update that the vendor needs to vet first permalink fedilink source parent