• 15 Posts
  • 335 Comments
Joined 1 year ago
cake
Cake day: June 30th, 2025

help-circle
  • Again i don’t know for sure but from my understanding to answer this question and the one you asked ironblossom.

    If a company accepts payment and ships to a fowarding service knowing it is going to a certain country then that is legally the same as if they shipped it themselves.

    If their product is not certified to be sold in that country the seller now can face heavy fines.

    If their product is defective and causes damage and they don’t have insurance for that country then the seller can be on the hook for heavy payouts.

    To prevent this the seller must block the sale.















  • Yes that is possible in the technical sense, possible in the sense that i can make it idk.

    A big part of it is regulation i believe, i also don’t know it fully so take this with a grain of salt but i believe there is alot of regulation that must make it so that users are not allowed to modify the radio, now i think this doesn’t forbid open source but it does forbid the user being able to actually change it, as far as i understand atleast.



  • Not exactly,

    fingerprintd really is a package for FP6 style devices, adding support for different devices to it will require alot of work, not sure if i would call it a rewrite as the better approach is probably a new package for this hardware that provides the same interface.

    For imsd the story is different, most of it is ims code that doesn’t care what the underlying hardware is, adding another modem type here is not alot of work, but i was also looking for a QMI compatible modem in which case it will just work with minimal changes.



  • I wasn’t trying to deflect my apologies, it was a genuine question if such audits are the norm, and if so i would hope it to be possible to do such an external security audit for a reasonable price.

    If we are talking about external surface like the phone being seized no i don’t think so, fingerprintd is pretty much the coupling between the trustlet and userspace, it only authenticates once the trustlet says so, so any attack surface lies in the trustlet, which sadly is closed source.

    Fingerprintd is in control of the size of this surface however as it passes arguments that control it, i will make these arguments user configurable so users can decide for themselves.