Live data from Hacker News

Your computer should say what you tell it to say

eff.org

11–20 of 263 posts

Re: Your computer should say what you tell it to say

#11
I agree with most of this, but one nit pick:

> Originally, secure computing relied on a second processor - a "Technical Protection Module" or TPM - to monitor the parts of your computer you directly interact with.

TPM stands for Trusted Platform Module, not Technical Protection Module

Re: Your computer should say what you tell it to say

#12

That's a very well-written explanation! I would hope that we see this kind of explanation more frequently.

So much better written than the articles that were at the top of HN originally. People somehow thought this would mean checking for ad block? The original proposal specifically called out that browser extensions are completely unrelated to WEI, which just calls into existing OS and TPM-based attestation APIs and makes the status of this attestation available to sites.

Re: Your computer should say what you tell it to say

#14
post #10

I mean, devil's advocate here, this tech already exists and the question is do we do client attestation in a browser or pretend remote attestation doesn't exist. If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app? I'm not trying to argue in favor of WEI, I just think this doesn't magically disappear if Google doesn't implemen…

The problem is, this is very open (or even designed) to be abused by their implementers. It's akin to having only Microsoft as the Secure Boot key authority.

Mobile devices already has tons of attestation features. Secure enclaves, security processors, cryptographic capabilities of SIM cards (e.g. I carry my private key inside my SIM card, and use it as a wet signature, legally).

We do not need this tech which can and will be abused to lock any tech savvy person from daily internet based on arbitrary rules. There are no checks and balances. This is a very broad set of capabilities which is forced upon users.

This is no proposal, or experiment. It's a force-push attempt.

Re: Your computer should say what you tell it to say

#15
post #10

I mean, devil's advocate here, this tech already exists and the question is do we do client attestation in a browser or pretend remote attestation doesn't exist. If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app? I'm not trying to argue in favor of WEI, I just think this doesn't magically disappear if Google doesn't implemen…

You are correct, and that is fine. If the ecosystem becomes "You control your browser but not the apps on your mobile device," that's pretty much the status quo.

Re: Your computer should say what you tell it to say

#16

The EFF stands alone in its commitment to actually speaking truth to power. The ACLU has become just another arm of the DNC, same with the SPLC etc - repeating CNN-esque talking points. Same with the NRA - milquetoast arm of those in power. The EFF will go after orgs that fund it, which requires true compunction. FIRE is a good replacement for the ACLU, FYI. And John Brown Gun Club is becoming a better NRA.

> John Brown Gun Club is becoming a better NRA.

JBCG doesn't really replace much of the NRA. Even if hypothetically people could join JBCG at mass scale, which they can't due to the way its structured.

The NRA-ILA is increasingly useless for 2A advocacy and legal efforts, but JBCG isn't replacing that at all. FPC, 2AF, to a lesser extent GOA do more there.

NRA courses are crufty but don't really have a replacement approaching anywhere near the same scale. Certainly not JBCG. Maybe USCCA for just the pistol side of things, but that has its own issues since their business model is fleecing people.

NRA competition... there's no replacement for bullseye, but that's because bullseye is becoming an afterthought compared to e.g. USPSA in a lot of areas... smallbore and air as a college&younger sport notwithstanding. And nothing is close to trap/skeet/sc in popularity in the US, but that's not NRA either.

NRA club/range support and insurance.... also nothing replaces this.

---

What JBCG has that the NRA doesn't, and never had, is the same thing that the black panthers had in the 60s - armed support of disenfranchised subsets of the population. It's harder for the police to shut you down, or stand and watch as an adjacent supremacist group shuts you down, if you have your own armed guards.

Same as armed guards prevented mobs from attacking schoolchildren during desegregation in the late 60s, you see JBCG in a lot of places protecting pride events, drag events, etc. 'cus the police often don't. (In the US, it's not the police's job to protect anyone, that's been tried in the Supreme Court multiple times)

Re: Your computer should say what you tell it to say

#18
post #10

I mean, devil's advocate here, this tech already exists and the question is do we do client attestation in a browser or pretend remote attestation doesn't exist. If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app? I'm not trying to argue in favor of WEI, I just think this doesn't magically disappear if Google doesn't implemen…

The problem is, this is very open (or even designed) to be abused by their implementers. It's akin to having only Microsoft as the Secure Boot key authority. Mobile devices already has tons of attestation features. Secure enclaves, security processors, cryptographic capabilities of SIM cards (e.g. I carry my private key inside my SIM card, and use it as a wet signature, legally). We do not need this tech which can an…

There were proposals for protecting against this in the WEI explainer under "Open Questions" https://github.com/RupertBenWiser/Web-Environment-Integrity/...

Re: Your computer should say what you tell it to say

#19
post #10

I mean, devil's advocate here, this tech already exists and the question is do we do client attestation in a browser or pretend remote attestation doesn't exist. If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app? I'm not trying to argue in favor of WEI, I just think this doesn't magically disappear if Google doesn't implemen…

> pretend remote attestation doesn't exist

This. Nothing in my skim of the spec prevents me from using your hacked machine as an attestation oracle. This does nothing but add additional value to compromising end user devices.

Re: Your computer should say what you tell it to say

#20

EDIT: Originally posited an incorrect fact here. I completely missed who wrote the article at hand (not sure why, but I didn't see the authors names) Good catch everyone

I'm puzzled by your comment. This is literally the article by him....
Post reply on HN