this post was submitted on 01 Aug 2026
1754 points (99.8% liked)
Technology
86849 readers
3806 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I’m talking about every service that you use your device for. They will not and should not trust some random phone owner that their device is secure and safe to let use their services. They will, however, trust Google saying that the device is secure and not tampered with - as they should.
Secure services should always have limited trust to user data and devices. Security built on 'Google says the device is secure' is broken. Yes, it is convenient fir service providers who do not care about their customer rights, but more for 'intellectual property' and liability.
Lots of apllications still work in web browsers without TPM-based, kernel level DRMs and many of them are still reasonably secure. They are built with the assumption user controls their device. This has always been possible and still is possible. Just inconvenient for corporations.
Websites and web applications don’t trust the user though, or at least they shouldn’t. They should all be doing server side verification and checking of anything the user inputs. This is why some banks will let you use their website on an old phone but not their app.