Live data from Hacker News

Your computer should say what you tell it to say

eff.org

61–70 of 263 posts

Re: Your computer should say what you tell it to say

#61

That's a very well-written explanation! I would hope that we see this kind of explanation more frequently.

So much better written than the articles that were at the top of HN originally. People somehow thought this would mean checking for ad block? The original proposal specifically called out that browser extensions are completely unrelated to WEI, which just calls into existing OS and TPM-based attestation APIs and makes the status of this attestation available to sites.

> People somehow thought this would mean checking for ad block

This is an obvious consequence of this proposal, yes. Ad-block prevention isn't an explicit goal, just a very obvious consequence when you create a mechanism that whereby attesters (OS) inform the server about the presence or absence of software on your computer. It doesn't require a logical leap, it's a plainly obvious use case.

> Goals:

> Allow web servers to evaluate the authenticity of the device and honest representation of the software stack and the traffic from the device.

Re: Your computer should say what you tell it to say

#62

> A handful of companies have established chokepoints between buyers and sellers, performers and audiences, workers and employers, as well as families and communities. When those companies refuse to deal with you, your digital life grinds to a halt This short paragraph summarizes the (ex-ante) improbably unusual situation we have drifted into. The negatively affected stakeholders being enumerated are more or less the…

See also the history of railroads and telecoms.

Re: Your computer should say what you tell it to say

#64

Earlier quoted context omitted.

that's all great but you realize a lot of readers here are not USA, eh? "web-TPM" needs to be named-and-shamed among literate people in all nations IMHO. It is clearly political -- there are private winners and public losers in the change to locked and enforced access to digital content on the Internet. Any commercial company in any country that can successfully block the roads and check ID will make money, and they…

Your ability to mischaracterize it as "webtpm" makes me question your credibility entirely. It's fine to be opposed to the proposal, but it would be best to stay truthful and not exaggerate.

the term is quoted -- informal for "something like that"

It is deliberately not a compliment

Re: Your computer should say what you tell it to say

#65

Earlier quoted context omitted.

It reduces control of my computer because without it my computer can identify itself to websites and advertisers in the way that I want, but with it, it can only use its TPM assigned identity. You can argue (I'd disagree) that it's a good thing that I can't make my computer spoof as something else, but unquestionably it does reduce my control.

> unquestionably it does reduce my control It doesn't reduce your control, you are still welcome to identify your computer however you want to websites by using a browser without WEI or disabling it. You will just have to live with the reality that a lot of servers aren't going to want to talk to your client.

Their point is that a browser with WEI reduces your control versus a browser without WEI. I would agree with them that it's definitional.

Re: Your computer should say what you tell it to say

#66

That's a very well-written explanation! I would hope that we see this kind of explanation more frequently.

So much better written than the articles that were at the top of HN originally. People somehow thought this would mean checking for ad block? The original proposal specifically called out that browser extensions are completely unrelated to WEI, which just calls into existing OS and TPM-based attestation APIs and makes the status of this attestation available to sites.

People think it's about checking for ad block because protecting ad revenue is the very first concern the proposal addresses. The obvious path is that Chrome implements WEI and disallows ad blocking, and then Google gradually starts pushing websites to favor approved browsers that don't allow ad blocking. Perhaps they pay out a bit extra for "authenticated" ad impressions made using an approved browser. Or they could start suspending AdSense accounts for "invalid traffic" (https://blog.google/products/ads-commerce/understanding-acco...) because a high percentage of visits have no WEI token or a token from an "unrecognized" browser. I'm sure you can imagine Google doing something like that: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

EFF clearly explains why the holdback mechanism doesn't make sense, and why the proposal authors' personal beliefs are not relevant. What matters is what capabilities this technology allows, and what Google's corporate motivations are.

Re: Your computer should say what you tell it to say

#67

I agree with most of this, but one nit pick: > Originally, secure computing relied on a second processor - a "Technical Protection Module" or TPM - to monitor the parts of your computer you directly interact with. TPM stands for Trusted Platform Module, not Technical Protection Module

The EFF are known for their alternate expansions at times. By far not as bad as the FSF, but they do tend to editorialize.

This however, absolutely sounds like someone being snarky.

Re: Your computer should say what you tell it to say

#68

> A handful of companies have established chokepoints between buyers and sellers, performers and audiences, workers and employers, as well as families and communities. When those companies refuse to deal with you, your digital life grinds to a halt This short paragraph summarizes the (ex-ante) improbably unusual situation we have drifted into. The negatively affected stakeholders being enumerated are more or less the…

See also the history of railroads and telecoms.

Also every industry in Canada

Re: Your computer should say what you tell it to say

#69

Earlier quoted context omitted.

That's wild. It seems these blog posts are outsourced. Edit: I'm wrong about this one. It's an actual article, and a pretty good one at that. But it is either a mistake or they are introducing an alternate expansion for TPM (other acronyms have been given different sets of words).

Or written with help from chat gtp, I've seen it hallucinate similar mistakes before.

Ah actually it is ChatGPT, you’ve made a common mistake. Perhaps you are an AI?

As we all know, ChatGPT stands for “Chat General Purpose Tool”, as it is an artificial general intelligence.

Re: Your computer should say what you tell it to say

#70

I agree with most of this, but one nit pick: > Originally, secure computing relied on a second processor - a "Technical Protection Module" or TPM - to monitor the parts of your computer you directly interact with. TPM stands for Trusted Platform Module, not Technical Protection Module

That's wild. It seems these blog posts are outsourced. Edit: I'm wrong about this one. It's an actual article, and a pretty good one at that. But it is either a mistake or they are introducing an alternate expansion for TPM (other acronyms have been given different sets of words).

I'm guessing it's an alternate expansion that was popularized by some group who was deeply doubtful about this technology.

"Trusted Platform Module" sounds good. But what it actually means is that the platform can be "trusted" to place the interests of third parties over the owner of the device. Stallman referred to it as a "Treacherous Platform Module" because he saw it as betraying the user.

I'm guessing that "Technical Protection Module" is a similar attempt to "de-propagandize" the acronym, and that it caught on with some group of users long ago.

Post reply on HN