> Originally, secure computing relied on a second processor - a "Technical Protection Module" or TPM - to monitor the parts of your computer you directly interact with.
TPM stands for Trusted Platform Module, not Technical Protection Module
11–20 of 263 posts
> Originally, secure computing relied on a second processor - a "Technical Protection Module" or TPM - to monitor the parts of your computer you directly interact with.
TPM stands for Trusted Platform Module, not Technical Protection Module
That's a very well-written explanation! I would hope that we see this kind of explanation more frequently.
Remember: upvoting the EFF's articles is good, but you (yes, you!) can also donate to them to help with these campaigns!
I mean, devil's advocate here, this tech already exists and the question is do we do client attestation in a browser or pretend remote attestation doesn't exist. If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app? I'm not trying to argue in favor of WEI, I just think this doesn't magically disappear if Google doesn't implemen…
Mobile devices already has tons of attestation features. Secure enclaves, security processors, cryptographic capabilities of SIM cards (e.g. I carry my private key inside my SIM card, and use it as a wet signature, legally).
We do not need this tech which can and will be abused to lock any tech savvy person from daily internet based on arbitrary rules. There are no checks and balances. This is a very broad set of capabilities which is forced upon users.
This is no proposal, or experiment. It's a force-push attempt.
I mean, devil's advocate here, this tech already exists and the question is do we do client attestation in a browser or pretend remote attestation doesn't exist. If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app? I'm not trying to argue in favor of WEI, I just think this doesn't magically disappear if Google doesn't implemen…
The EFF stands alone in its commitment to actually speaking truth to power. The ACLU has become just another arm of the DNC, same with the SPLC etc - repeating CNN-esque talking points. Same with the NRA - milquetoast arm of those in power. The EFF will go after orgs that fund it, which requires true compunction. FIRE is a good replacement for the ACLU, FYI. And John Brown Gun Club is becoming a better NRA.
JBCG doesn't really replace much of the NRA. Even if hypothetically people could join JBCG at mass scale, which they can't due to the way its structured.
The NRA-ILA is increasingly useless for 2A advocacy and legal efforts, but JBCG isn't replacing that at all. FPC, 2AF, to a lesser extent GOA do more there.
NRA courses are crufty but don't really have a replacement approaching anywhere near the same scale. Certainly not JBCG. Maybe USCCA for just the pistol side of things, but that has its own issues since their business model is fleecing people.
NRA competition... there's no replacement for bullseye, but that's because bullseye is becoming an afterthought compared to e.g. USPSA in a lot of areas... smallbore and air as a college&younger sport notwithstanding. And nothing is close to trap/skeet/sc in popularity in the US, but that's not NRA either.
NRA club/range support and insurance.... also nothing replaces this.
---
What JBCG has that the NRA doesn't, and never had, is the same thing that the black panthers had in the 60s - armed support of disenfranchised subsets of the population. It's harder for the police to shut you down, or stand and watch as an adjacent supremacist group shuts you down, if you have your own armed guards.
Same as armed guards prevented mobs from attacking schoolchildren during desegregation in the late 60s, you see JBCG in a lot of places protecting pride events, drag events, etc. 'cus the police often don't. (In the US, it's not the police's job to protect anyone, that's been tried in the Supreme Court multiple times)
Originally posited an incorrect fact here. I completely missed who wrote the article at hand (not sure why, but I didn't see the authors names)
Good catch everyone
I mean, devil's advocate here, this tech already exists and the question is do we do client attestation in a browser or pretend remote attestation doesn't exist. If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app? I'm not trying to argue in favor of WEI, I just think this doesn't magically disappear if Google doesn't implemen…
The problem is, this is very open (or even designed) to be abused by their implementers. It's akin to having only Microsoft as the Secure Boot key authority. Mobile devices already has tons of attestation features. Secure enclaves, security processors, cryptographic capabilities of SIM cards (e.g. I carry my private key inside my SIM card, and use it as a wet signature, legally). We do not need this tech which can an…
I mean, devil's advocate here, this tech already exists and the question is do we do client attestation in a browser or pretend remote attestation doesn't exist. If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app? I'm not trying to argue in favor of WEI, I just think this doesn't magically disappear if Google doesn't implemen…
This. Nothing in my skim of the spec prevents me from using your hacked machine as an attestation oracle. This does nothing but add additional value to compromising end user devices.
EDIT: Originally posited an incorrect fact here. I completely missed who wrote the article at hand (not sure why, but I didn't see the authors names) Good catch everyone