Live data from Hacker News

Your computer should say what you tell it to say

eff.org

121–130 of 263 posts

Re: Your computer should say what you tell it to say

#121

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

Then we'd better find ways of fooling or defeating WEI. "Tamper proof" indeed. It's just OS DRM. We've cracked DRM, we can crack this.

Re: Your computer should say what you tell it to say

#122
post #73
post #32

Earlier quoted context omitted.

They don't have to be outsourced to this to happen. To put out lengthy press-releases, you hire a copywriter. You don't ask an engineer to write them. People make mistakes sometimes. And this one is not a huge one -- the meaning is conveyed fine.

I've also seen that exact incorrect explanation of what "TPM" stands for in several other places now. I'm guessing that someone authoritative made the error and now it's being propagated by people who aren't otherwise familiar with the terminology.

Google/Bing say otherwise, at least when it comes to the exact pharase "Technical Protection Module".

Re: Your computer should say what you tell it to say

#123

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

my experience with banks has been the opposite - they're always a ways behind the rest of the web on security measures. some banks are still rolling out 2fa. and look how horrifically insecure credit cards are. not because they don't care, but because they see technical measures as only a small piece of their overall security strategy, and online access as only a small part of their business that they consider untrustworthy no matter how much security is implemented.

where most of the web treats authenticated users as trusted, banks still treat an authenticated user as mostly untrustworthy, and all of their actions as still being a potential risk, so securing the authentication isn't so important.

Re: Your computer should say what you tell it to say

#124

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

While I'm willing to believe banks are very security minded in terms of their core infrastructure, banks do not appear to be with regards to their customer access and usually seem to move very slowly to secure that end of things. Hell, many/most of these large institutions seem to still only support SMS for 2FA and even that's a relatively recent introduction to actually mandate. Which is to say, I expect banks to be…

> I expect banks to be about the very last significant account you use to mandate this technology

Unless Google happens to make fat campaign donations or post-office job offers to elected officials who can insure WEI becomes mandated for banks.

In the face of this, what banks want won't matter much.

Re: Your computer should say what you tell it to say

#125

Earlier quoted context omitted.

I don't do mobile apps. What I'll do instead (and, honestly, this is what I already mostly do anyhow so it's not really a sacrifice) is physically go to the bank branch to conduct my business.

At my bank, they will then send you to the online banking, or the phone (with it's 20 min plus waits). The Mobile app is required to use the debit card anywhere but card present, because 2fa. The Mobile app is required to do interesting things on the website, because of their 2fa. The iPad can't use their website (because reasons, they think it's mobile) and can't use the mobile app because it's not the configured ph…

If things were like that where I live, then I'd have to have a different response, obviously. I'm sorry that your options are so limited.

I'm not sure what my response would be, but I'd probably lean toward having a separate device that's acceptable to the bank and that I use only for banking purposes. But I don't know.

Re: Your computer should say what you tell it to say

#126
post #70

Earlier quoted context omitted.

That's wild. It seems these blog posts are outsourced. Edit: I'm wrong about this one. It's an actual article, and a pretty good one at that. But it is either a mistake or they are introducing an alternate expansion for TPM (other acronyms have been given different sets of words).

I'm guessing it's an alternate expansion that was popularized by some group who was deeply doubtful about this technology. "Trusted Platform Module" sounds good . But what it actually means is that the platform can be "trusted" to place the interests of third parties over the owner of the device. Stallman referred to it as a "Treacherous Platform Module" because he saw it as betraying the user. I'm guessing that "Tec…

That makes sense, but instead of long ago it would be today, as the search engines aren't showing prior use of "Technical Protection Module". I don't know if will catch on or not.

Re: Your computer should say what you tell it to say

#127
post #10

I mean, devil's advocate here, this tech already exists and the question is do we do client attestation in a browser or pretend remote attestation doesn't exist. If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app? I'm not trying to argue in favor of WEI, I just think this doesn't magically disappear if Google doesn't implemen…

The problem is, this is very open (or even designed) to be abused by their implementers. It's akin to having only Microsoft as the Secure Boot key authority. Mobile devices already has tons of attestation features. Secure enclaves, security processors, cryptographic capabilities of SIM cards (e.g. I carry my private key inside my SIM card, and use it as a wet signature, legally). We do not need this tech which can an…

Based on what you're saying though, it's already been forced on users through mobile devices. This is the next step in a series of steps which weren't argued against. It's not that we don't need this tech, is that we didn't need this tech and are making noise and it now.

Re: Your computer should say what you tell it to say

#128

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

Then we'd better find ways of fooling or defeating WEI. "Tamper proof" indeed. It's just OS DRM. We've cracked DRM, we can crack this.

I suspect cracking this will involve attacks like the recent Tesla one that require an extreme amount of technical skill and risk of destroying/damaging the system in the process. Then cue the cat & mouse game. Widespread breaking of it is not going to be remotely practical.

Re: Your computer should say what you tell it to say

#129

That's a very well-written explanation! I would hope that we see this kind of explanation more frequently.

Nope, not really. Still looks like the equivalent of anti-encryption people saying "think of the children". I still see no explanation on how WEI will magically change the behavior of website operators. They can already take steps to block unwanted clients, but no one is in any significant way which hinders the "open internet". WEI is meaningless unless Apple implements it. The only effect the current discussion will…

They already have implemented it. We and the eff for that matter made not a peep, nor mentioned it.

https://httptoolkit.com/blog/apple-private-access-tokens-att...

Re: Your computer should say what you tell it to say

#130
post #85

Earlier quoted context omitted.

Also every industry in Canada

The solution in Canada is to break up some of these huge companies. The free market can solve things, but only if there's a free market. When you have 1 or 2 companies, there's no competition.

> The solution in Canada is to break up some of these huge companies. The free market can solve things, but only if there's a free market.

I'm not familiar with Canada but this sounds like oversight there is similar to how the US DoJ operates - which is to say it has a long history of rubberstamping (massive, competition-killing) mergers

Post reply on HN