Live data from Hacker News

Your computer should say what you tell it to say

eff.org

131–140 of 263 posts

Re: Your computer should say what you tell it to say

#131

Earlier quoted context omitted.

You'll likely be ushered to their mobile app instead.

I don't do mobile apps. What I'll do instead (and, honestly, this is what I already mostly do anyhow so it's not really a sacrifice) is physically go to the bank branch to conduct my business.

I don't know about your country but here the only people who physically go to the bank are 80+ grannies and granddads who think they're too old to learn this bloody computer stuff, and who are also willing to pay exorbitant 10-30 monetary units for each bill paid by a physical person in the physical bank, and to do even that they must accept that it's ok if you have to book an appointment at the bank's counter in advance.

Re: Your computer should say what you tell it to say

#132
post #97

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

> Once it exists though, you can be sure it will become a standard practice requirement Yes, this seems inevitable. At which point, I will no longer be using the bank's website. > they'll seem absurd and won't last long in that position. I'm not sure what you mean here, though. People who object to ubiquitous surveillance don't seem absurd to most (even those who aren't so upset about it), and they certainly aren't c…

Given that most people don't use ad blockers, I suspect most people will not stop using the website, at which point, it becomes safe to assume most people will have a browser it works with. Once that point is reached, there's no reason it wouldn't proliferate to any number of sites, including ones you likely do use.

Re: Your computer should say what you tell it to say

#133
post #67

I agree with most of this, but one nit pick: > Originally, secure computing relied on a second processor - a "Technical Protection Module" or TPM - to monitor the parts of your computer you directly interact with. TPM stands for Trusted Platform Module, not Technical Protection Module

The EFF are known for their alternate expansions at times. By far not as bad as the FSF, but they do tend to editorialize. This however, absolutely sounds like someone being snarky.

I'm with the parent on this. Defining TPM correctly is just extending basic kindness to readers.

Re: Your computer should say what you tell it to say

#134
post #131

Earlier quoted context omitted.

I don't do mobile apps. What I'll do instead (and, honestly, this is what I already mostly do anyhow so it's not really a sacrifice) is physically go to the bank branch to conduct my business.

I don't know about your country but here the only people who physically go to the bank are 80+ grannies and granddads who think they're too old to learn this bloody computer stuff, and who are also willing to pay exorbitant 10-30 monetary units for each bill paid by a physical person in the physical bank, and to do even that they must accept that it's ok if you have to book an appointment at the bank's counter in adv…

It's nothing like that here in my part of the US, fortunately. I am becoming increasingly aware at how lucky I am about this in these comments, though! As I said in another comment, if I had these obstacles, it would absolutely alter my response to this.

I don't pay my bills at a bank or bank website regardless, there is no surcharge for going to a bank's physical location, and I don't have to make an appointment.

And people who go to branches aren't exclusively elderly and/or technophobes -- but even if they were, what does that matter?

Re: Your computer should say what you tell it to say

#135

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

my experience with banks has been the opposite - they're always a ways behind the rest of the web on security measures. some banks are still rolling out 2fa. and look how horrifically insecure credit cards are. not because they don't care, but because they see technical measures as only a small piece of their overall security strategy, and online access as only a small part of their business that they consider untrus…

Some banks are definitely behind on the curve, but notably I think that tends to be around customer-facing stuff. Given that whatever they use has to work for very elderly people as well young people, it surely makes it difficult to move/change things. WEI though is entirely on the backend though. It can be implemented as soon as the major OSes have it integrated, and it requires nothing from the user (besides installing their updates, which is mostly forced).

Re: Your computer should say what you tell it to say

#136
post #70

Earlier quoted context omitted.

That's wild. It seems these blog posts are outsourced. Edit: I'm wrong about this one. It's an actual article, and a pretty good one at that. But it is either a mistake or they are introducing an alternate expansion for TPM (other acronyms have been given different sets of words).

I'm guessing it's an alternate expansion that was popularized by some group who was deeply doubtful about this technology. "Trusted Platform Module" sounds good . But what it actually means is that the platform can be "trusted" to place the interests of third parties over the owner of the device. Stallman referred to it as a "Treacherous Platform Module" because he saw it as betraying the user. I'm guessing that "Tec…

Exactly. Whenever the name of some computing concept makes the end user into the adversary, we should de-propagandize that name. See also: Digital Rights Management (DRM). Whose "rights" are benefiting from it? Certainly not the users'. See also: Copy Protection. What is being protected? Not the user.

Re: Your computer should say what you tell it to say

#137
post #132
post #97

Earlier quoted context omitted.

> Once it exists though, you can be sure it will become a standard practice requirement Yes, this seems inevitable. At which point, I will no longer be using the bank's website. > they'll seem absurd and won't last long in that position. I'm not sure what you mean here, though. People who object to ubiquitous surveillance don't seem absurd to most (even those who aren't so upset about it), and they certainly aren't c…

Given that most people don't use ad blockers, I suspect most people will not stop using the website, at which point, it becomes safe to assume most people will have a browser it works with. Once that point is reached, there's no reason it wouldn't proliferate to any number of sites, including ones you likely do use.

Indeed, and this is why I'm very opposed to the WEI idea. It will make the web even smaller and less useful.

> Given that most people don't use ad blockers

In the US, 40% of people do use ad blockers. That's certainly not "most", but it is a large enough number to be significant.

Re: Your computer should say what you tell it to say

#138
post #10

I mean, devil's advocate here, this tech already exists and the question is do we do client attestation in a browser or pretend remote attestation doesn't exist. If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app? I'm not trying to argue in favor of WEI, I just think this doesn't magically disappear if Google doesn't implemen…

This is entirely about Google trying to deal with ad click fraud. They desperately want a solution in the browser.

They will ship this, standard or not. But I don't see a reason for Apple to ship this in Safari, or Firefox neither. So I expect this will be a real test of Chrome's market power. Will any sites start blocking non-WEI browsers? Locking out iPhones seems insane. Or will we see differential ad rates for WEI environments?

Re: Your computer should say what you tell it to say

#139

>You can choose not to send this to the remote server, but you lose the ability to send an altered or randomized description of your device and its software if you think that's best for you. The EFF is being misleading here by conflating the attestation taken and fingerprintable information like a user agent. An attestation taken does not contain information about the device that can be used to identify since the dat…

So, part of an ongoing campaign to stamp out everything was good and different about the web?

Re: Your computer should say what you tell it to say

#140
post #97

Earlier quoted context omitted.

> Once it exists though, you can be sure it will become a standard practice requirement Yes, this seems inevitable. At which point, I will no longer be using the bank's website. > they'll seem absurd and won't last long in that position. I'm not sure what you mean here, though. People who object to ubiquitous surveillance don't seem absurd to most (even those who aren't so upset about it), and they certainly aren't c…

> I will no longer be using the bank's website That's a great temporary measure, but once this has rolled out everywhere and is part of standard commercial experiences, are you really willing to completely opt out of online banking because you're not permitted to send fake browser identification? It's a fine philosophical position, but it feels akin to refusing to use public streets because of the existence of survei…

Unless they're going to trust my own attestion provider (unlikely, and then what's the point?), I would have to buy another computer to use online banking. My computer does not have attestation. I'm not going to move to Windows just to use my bank's website (and I think I saw Windows 11 requires a new computer anyway, exactly because of this attestation stuff?). All of the programs I use and workflow are on Linux. I can't virtualize it since that's the point.

Attestation requirements from banks would mean I must run an OS with adware and spyware built in to use online banking. It's not (just) about browsers.

Post reply on HN