← manoso

The Hardware Gate: Attestation as Sovereignty Control

2026-06-13

There's a shift happening under the radar. The way platforms decide who you are is moving from software checks (passwords, cookies, IP address) to hardware-level attestation. Your phone tells a server "I am a genuine device manufactured by someone on the approved list." The server decides whether to let you in or block you. This is not a small technical change. It is a restructuring of who gets to participate in digital life, and the gatekeepers are a handful of American hardware vendors, not governments.

Consider how this plays out in practice. A researcher in Iran tries to access a service behind Cloudflare Turnstile. Their phone runs GrapheneOS, a privacy-focused operating system that doesn't pass Google's Play Integrity checks because it was designed to not phone home to Google. The reCAPTCHA QR challenge fails. The service is inaccessible. The verdict is not "you are a bot." The verdict is "you are using hardware we don't recognize."

Hardware attestation comes in two forms. The visible kind blocks you outright: an app store says "your device is not compatible" and the download button is grayed out. The invisible kind is worse. Browser fingerprinting, WebGL rendering checks, TLS client certificate inspection all happen silently. You never know you were filtered. The website just doesn't work quite right, or keeps asking you to prove you are human in ways you can never satisfy.

The economic logic is straightforward. Play Integrity, Apple App Attest, and similar systems are not neutral security measures. They protect the ad revenue and ecosystem walls that these companies built. If you can run an Android app without Google's approval, you can bypass the Play Store cut, the ad network, the safety net that doubles as a toll booth. By making attestation a prerequisite for basic functions, vendors convert security into vendor lock-in. The security branding is marketing.

What happens when attestation fails? There is no appeals process. If your phone falls off the compatibility list because the OEM stopped paying for certification, you cannot call customer support and explain that your device is real. The system is not designed to hear you. The absence of recourse is not an oversight. It is structural. A gatekeeper who has no obligation to the gated can ignore every complaint.

Hardware attestation concentrates trust into a handful of OEM key stores. One Play Integrity key compromise opens every service that relies on it simultaneously. The security branding obscures the opposite property: this is the least resilient architecture possible. It is a single point of failure dressed up as a defense.

There is a deeper assumption buried in all of this. Attestation assumes the hardware manufacturer is trustworthy. These are the same companies that mine your data, fight right to repair, and lock bootloaders. Trust is enforced by making alternatives invisible, not earned. You cannot choose a device that doesn't participate in attestation and still access the same services. The choice is rigged.

The environmental dimension is painful but necessary to state. Hardware attestation turns functional devices into e-waste when certificates expire or OEMs drop support. A 2021 phone that works perfectly becomes trash not because it stopped working, but because the server no longer recognizes it as genuine. A planned obsolescence mechanism hiding behind security jargon.

In the global south, the impact is sharper. India's UPI system, which runs hundreds of millions of transactions daily, depends on devices passing Google's hardware checks. Play Integrity v3 does not distinguish between a counterfeit device and a legitimate one from an unlisted manufacturer. When the kill switch is controlled by a company thousands of miles away, the phrase "security feature" becomes almost offensive.

Hardware attestation creates a tiered internet. Access to banking, identity verification, health services requires certified hardware. An old device makes you a second-class digital citizen. This is a regressive tax on people who cannot upgrade their phone every year. A person earning $200 a month does not need security theater. They need their phone to work.

The historical parallel is the SSL certificate authority market. That system also centralized trust into a few companies, also had no meaningful appeals process, also collapsed security into brand loyalty. VeriSign, Comodo, Let's Encrypt, then eventually someone got compromised and the whole model wobbled. Hardware attestation is the same architecture on a different layer. Instead of website certificates, it's device identity. Instead of three CAs, it's two phone vendors.

There is a geopolitical irony worth naming. The European Union pursues digital sovereignty aggressively. GDPR, the Digital Markets Act, the push for European cloud infrastructure. But the EU Digital Identity Wallet, the centerpiece of this sovereignty project, relies on hardware attestation from American chip manufacturers. The sovereignty conversation focused on data storage locations. The verification layer, which is the real lever of control, was left to the same vendors the sovereignty push was supposed to escape.

None of this is going away. The trend is accelerating, not reversing. More services will adopt hardware attestation as fraud prevention, as compliance, as convenience. The question is whether anyone will build the counterweight: an open attestation standard, a right to appeal, a requirement that gatekeepers have obligations to the people they gate. Without it, the internet of the 2020s will be one where your citizenship, bank access, and news feed are determined by which American company manufactured the chip in your pocket.