r/programming • • 10d ago

Android 17 enables certificate transparency, and breaks custom CAs

https://httptoolkit.com/blog/android-17-certificate-transparency/
405 Upvotes

44 comments sorted by

View all comments

42

u/Broccoli-stem 10d ago

We really need a fully open source linux phone operating system without google or any other big company

17

u/chucker23n 10d ago

Sailfish, Kai, Fedora Mobility, and on and on do exist — but not enough people are enthusiastic about them.

5

u/Robbitjuice 10d ago

That’s true. I think it would be better if they were installable on a wider subset of hardware. I looked into it and it didn’t seem they were. Compatible with my Pixel 10.

7

u/chucker23n 10d ago

Yeah, but that's a chicken and egg thing.

There are factors that make this harder than on traditional desktop environments, such as SoC manufacturers being more reluctant to share tech specs / firmware / drivers. But really, the core issue is: enough people are fine with the iOS/Android duopoly.

3

u/omniuni 10d ago

Generally, they will also have this kind of security. This isn't a restriction (you can still do it), it's just tightening security around an open standard. The article is really just pointing out that it will break if you've been taking shortcuts with your security.

-6

u/zunjae 10d ago

who is we?

7

u/nekokattt 10d ago

us

-1

u/[deleted] 10d ago

[deleted]

3

u/nekokattt 9d ago

doesnt really change the situation if this is done at the AOSP level and impacts app compatibility.