Live data from Hacker News

Your computer should say what you tell it to say

eff.org

151–160 of 263 posts

Re: Your computer should say what you tell it to say

#151

I read the entire thing and it’s not clear how this reduces control of your own computer. It seems the premise is that those with a computer should be able to access others servers wholesale unconditionally. This premise is obviously wrong. > It also raises the barrier to entry for new browsers, something Google employees acknowledged in an unofficial explainer for the new feature, Web Environment Integrity (WEI). Th…

It reduces control of my computer because without it my computer can identify itself to websites and advertisers in the way that I want, but with it, it can only use its TPM assigned identity. You can argue (I'd disagree) that it's a good thing that I can't make my computer spoof as something else, but unquestionably it does reduce my control.

the better argument is just flipping the perspective. if your computer runs a web server this increase the control because without it other computers can connect to it and lie about their identity. that's not to say I think this is a good thing, I just don't think control over your computer is a good argument when both sides of a connection are computers, and both operators want not just control over their computer but also what the other computer can do.

Re: Your computer should say what you tell it to say

#152

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

I work in a bank. Until a year ago, our passwords are 8 characters max, no special characters, upper and lowercase letters are equal. We were running IE7 up until 2 years ago. A huge amount of the business is still organized around sending excel sheets to each other, with no sidechannel validation. The fact that you recieved an excel sheet from some email is treated as proof that it's valid. Last I checked we were al…

> I have no doubt they will implement WEI, but it will not bring security.

This is precisely OP’s point. WEI will quickly dominate despite having nothing to do with securing anyone.

Re: Your computer should say what you tell it to say

#153

Remember: upvoting the EFF's articles is good, but you (yes, you!) can also donate to them to help with these campaigns!

I had donated to the EFF in the past, but their stance[1] that CDNs/hosted services shouldn't be allowed to choose the customers they are willing work with is not only wrong, it's causes harm[2]. [1] https://www.eff.org/press/releases/international-coalition-r... [2] https://blog.cloudflare.com/kiwifarms-blocked/

You know what I love about donating to EFF? They actually ask you which positions of theirs you agree with and will only use your money on those issues if you ask them to.

Re: Your computer should say what you tell it to say

#154

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

Then we'd better find ways of fooling or defeating WEI. "Tamper proof" indeed. It's just OS DRM. We've cracked DRM, we can crack this.

The idea of relying on cracks / security flaws to get basic freedom causes me great anxiety. Sure, it can be cracked. It shouldn't have to be because it shouldn't exist to begin with.

Meanwhile, arms race being what it will, the freedom gained will be short-lived and can't be relied-upon.

Re: Your computer should say what you tell it to say

#155

Earlier quoted context omitted.

Then we'd better find ways of fooling or defeating WEI. "Tamper proof" indeed. It's just OS DRM. We've cracked DRM, we can crack this.

The idea of relying on cracks / security flaws to get basic freedom causes me great anxiety. Sure, it can be cracked. It shouldn't have to be because it shouldn't exist to begin with. Meanwhile, arms race being what it will, the freedom gained will be short-lived and can't be relied-upon.

Mr. Anderson... don't you like the idea of a future where caring about privacy and control means you're marginalized to the sewers of a Matrix arcology, eating nutrient slurry on the Nebuchadnezzar?

Re: Your computer should say what you tell it to say

#156

The EFF stands alone in its commitment to actually speaking truth to power. The ACLU has become just another arm of the DNC, same with the SPLC etc - repeating CNN-esque talking points. Same with the NRA - milquetoast arm of those in power. The EFF will go after orgs that fund it, which requires true compunction. FIRE is a good replacement for the ACLU, FYI. And John Brown Gun Club is becoming a better NRA.

While I agree that the ACLU has become defanged, there are many more civil liberties to protect beyond simply free speech, which seems to be the only concern of FIRE.

I agree with you, but I don't see a big attack on freedom of religion, assembly (post COVID) or movement lately. Freedom of Speech is under massive, coordinated attack by gigacorporations and https://freddiedeboer.substack.com/p/please-just-fucking-tel...

Re: Your computer should say what you tell it to say

#157

Earlier quoted context omitted.

> I will no longer be using the bank's website That's a great temporary measure, but once this has rolled out everywhere and is part of standard commercial experiences, are you really willing to completely opt out of online banking because you're not permitted to send fake browser identification? It's a fine philosophical position, but it feels akin to refusing to use public streets because of the existence of survei…

> are you really willing to completely opt out of online banking Sure, why not? It's not like it's a huge sacrifice on my part. It's just a little reduction in convenience. No big deal. > because you're not permitted to send fake browser identification? That's not the issue for me at all. The issue is if sites require me to use specific browsers, to not use specific extensions, to not be able to modify the browsers,…

> Sure, why not? It's not like it's a huge sacrifice on my part. It's just a little reduction in convenience. No big deal.

I can easily imagine a world where in ~20-30 years, there are no bank branches or phones or ATM machines or cash--because 99.99% of people have no interest in using those things anymore. In that world, suddenly it becomes an almost insurmountable inconvenience not to acquiesce to whatever is required to use online banking.

Re: Your computer should say what you tell it to say

#158
post #151

Earlier quoted context omitted.

It reduces control of my computer because without it my computer can identify itself to websites and advertisers in the way that I want, but with it, it can only use its TPM assigned identity. You can argue (I'd disagree) that it's a good thing that I can't make my computer spoof as something else, but unquestionably it does reduce my control.

the better argument is just flipping the perspective. if your computer runs a web server this increase the control because without it other computers can connect to it and lie about their identity. that's not to say I think this is a good thing, I just don't think control over your computer is a good argument when both sides of a connection are computers, and both operators want not just control over their computer b…

That's fair, but it seems to me they could've done it differently -- require a signature from the clients but allow them to produce an unbounded number of valid unique signatures that are securely but anonymously tied to the client TPM. In other words the client would still be able to present a validated anonymized identity, but would not be able to generate someone else's signatures, and private-key-based revocation could still be available to deal with rogue TPMs.

Re: Your computer should say what you tell it to say

#159
Have these people heard of the iPhone? It came out in 2007. That's 16 years ago. It was never controlled by its users, and that enabled many apps and features, like disappearing messages, that are impossible on devices that are controlled by their users.

I think after 16 years it's time to admit that this model is here to stay, and the only question is whether the web supports it, or whether there will be certain apps and features that will never be available on the web.

Post reply on HN