garfnodie The phone is running. Is that not enough to know that particular stuff is good?
I would say that for most users, checking the verified boot key hash on the yellow "another operating system" screen, digit by digit, once, is plenty. Some users don't do that, and honestly for most of them that's fine.
But some people running GrapheneOS (think: journalists, lawyers, human rights activists) are concerned about people with substantial resources are actively trying to break into their devices. For example, some people are flashing GrapheneOS from a device that might potentially be infected by malware designed to pass an infection on to a GrapheneOS device as it is being flashed. Auditor provides some assurance to people who want to know that their phone isn't just running ok, but almost certainly running a specific software stack they have decided to trust.
garfnodie Maybe I'm still not getting it then. Was I supposed to be looking for something specific in all that text? There was nothing that said good or bad, pass or fail, so I don't know if it was good beyond the phone simply booting and appearing to work fine.
The expected "pass" situation for device-to-device is a green verdict (the second time it's run).
I think maybe part of the issue is that Auditor is designed to measure things that most people typically don't think about -- and, honestly, things that most people probably don't need to worry about. But I agree with you that the directions could be improved. For example, a series of screenshots would probably increase confidence for a lot of users.