Live data from Hacker News

Your computer should say what you tell it to say

eff.org

201–210 of 263 posts

Re: Your computer should say what you tell it to say

#201

Earlier quoted context omitted.

I had donated to the EFF in the past, but their stance[1] that CDNs/hosted services shouldn't be allowed to choose the customers they are willing work with is not only wrong, it's causes harm[2]. [1] https://www.eff.org/press/releases/international-coalition-r... [2] https://blog.cloudflare.com/kiwifarms-blocked/

You are essentially saying that we should have to ask permission from large corporations to be able to effectively run a website. For all practical purposes that means no free speech on the internet.

Freedom of speech meaning freedom from consequences has never existed, and will never exist.

Infringing on a company's freedom of association does not eliminate consequences for speech.

This is about freedom of association and the right (or lack thereof) to other people's broadcast equipment.

Re: Your computer should say what you tell it to say

#202

That's a very well-written explanation! I would hope that we see this kind of explanation more frequently.

Nope, not really. Still looks like the equivalent of anti-encryption people saying "think of the children". I still see no explanation on how WEI will magically change the behavior of website operators. They can already take steps to block unwanted clients, but no one is in any significant way which hinders the "open internet". WEI is meaningless unless Apple implements it. The only effect the current discussion will…

The missing explanation is to just assume websites become like smartphone apps in terms of restricting clients, for better or worse. This path has already been explored, so not much imagination is needed: https://stackoverflow.com/questions/27540545/how-to-prevent-...

Re: Your computer should say what you tell it to say

#203
post #98

Earlier quoted context omitted.

> WEI doesn't prevent you from participating in the web or needing to meet someone else's specification. You can even make an attestation service for your own browser. As always, Google will do its best to ensure it PRACTICALLY does, while denying it at the same time by pointing out that "you can make your own Google". > because the physical analog, fraud, is illegal, I don't know about the US, but in Poland abusive…

>Lying about the device seems to be the digital equivalent Not all lying is equal. If an ad network uses WEI to avoid lies made to defraud them their goal is not to be anticompetitive.

I can even agree here, however the question is - does this justify the entire mechanism when it's known it can be used for other purposes which are not as non-controversial as your examples.

Re: Your computer should say what you tell it to say

#204
post #89

> A handful of companies have established chokepoints between buyers and sellers, performers and audiences, workers and employers, as well as families and communities. When those companies refuse to deal with you, your digital life grinds to a halt This short paragraph summarizes the (ex-ante) improbably unusual situation we have drifted into. The negatively affected stakeholders being enumerated are more or less the…

> as if they already operate effective mind control at systemic scale. If the logical conclusion of your reasoning is a mass mind control conspiracy, you should revisit your assumptions. > somehow they can bully into submission basically the entire universe I don't think anyone is bullying all of society. I think most people just don't care. It's really not that crazy, no mind control involved. Just good old fashione…

Yeah this is a super deep issue but its not mind control.

It's a mix of middlemen being the only industry that can still extract more profit, and a level of control over markets by Capital that makes most opinions meaningless.

Its essentially a return to feudalism, where certain people own vast swaths of productive space, they're untouchable in the legal system and real life, and one is forced to work for them.

To escape the system means leaving behind most of society depending on your convictions. These groups can kill you physically(Monsanto poisoning people with pesticides) or metaphorically(you lose all connection to the general societal social media) and nothing can be done.

For the first one, if you were to suggest violence against those doing violence against you, you're essentially told that violence is never the answer, except when its in the form of collateral damage for profit motive.

For the latter, its not nearly as life ending, annoying, but not life ending or even altering unless your livelihood is based around grifting on social media. For social media it is ironically democratic, if most people find you to be an annoying asshole, they sorta kick you off so you leave everyone alone. No different than getting kicked out of a bar for demanding to see someone's genitals.

Re: Your computer should say what you tell it to say

#205

Earlier quoted context omitted.

While I'm willing to believe banks are very security minded in terms of their core infrastructure, banks do not appear to be with regards to their customer access and usually seem to move very slowly to secure that end of things. Hell, many/most of these large institutions seem to still only support SMS for 2FA and even that's a relatively recent introduction to actually mandate. Which is to say, I expect banks to be…

As the parent pointed out, banks don't care about customer access or even customer security per se. They care about not getting fined or accused of not being "as secure as possible." You and I know that using SMS for 2FA is a non-great idea. Banks mostly know it too. The reason they continue to use it is because regulators will not ding them for using it , and there's currently no better alternative that the average…

One of the banks I work with had 2FA fobs since the beginning of 2000s. Now they have the same "fob" as an app in the phone, and using it is mandatory IIRC.

Most banks lock your phone access to your IMEI + phone model + some phone specific data, so people knowing your details can't login without your phone. Web side needs 2FA or special activation depending on the bank.

Forgot your password? You need your biometric ID and your actual face to match at that very moment to make that work.

These are by regulations, yes, but this is very far from a "security theater".

Re: Your computer should say what you tell it to say

#206

Earlier quoted context omitted.

> An attestation taken does not contain information about the device that can be used to identify since the data the site gets is low entropy. Citation needed, how does WEI make it _impossible_ for attesters to return higher entropy information? Pinkie promises are insufficient. > WEI doesn't stop you from changing your user agent False, this is an explicit design goal: "Allow web servers to evaluate the authenticity…

>how does WEI make it _impossible_ for attesters to return higher entropy information? It isn't impossible, but doing so would violate users privacy which isn't the goal of the proposal. You don't need WEI to violate people's privacy. >False, this is an explicit design goal: "Allow web servers to evaluate the authenticity of the device and honest representation of the software stack and the traffic from the device."…

> but WEI is meant to be used in situations where lying should be illegal.

But here I once again have to point out that in practice this will look very different.

The practical effect is that if someone installs LineageOS or even AOSP to get rid of Google spyware and preinstalled bloatware, then these attestation checks will fail and that user will not be able to use apps that are necessary in practice.

The question is whether this is really a "side effect" or just the actual goal.

Re: Your computer should say what you tell it to say

#207
post #77

Earlier quoted context omitted.

I skimmed the link you provided, thanks. It looks like they propose to mix false signals to prevent this from being abused, but oh. That's easy to bypass. Require two attestations back to back to see whether they differ, or put up a page saying, "can you please try again?" The open question is circling around the question, can we make it work in a way, such that it doesn't work for bad guys, but works for good guys.…

We can't even agree on who the good guys and bad guys are. Is a bank bad for excluding certain browsers?

Yes. What about screen reading browsers?

What about neurodivergent people who cannot function on an "approved" OS because of the inherent ways it manages, stores, and presents information? What if that OS has an ACID compliant browser capable of accessing the banks website if they didn't have remote attestation?

What about the millions of people unable to afford to upgrade their hardware to Windows 11? Or that don't have TPM available and therefore can't use any other Windows version because 10 fell out of support, so they're running a Linux distro with an unapproved web browser?

Re: Your computer should say what you tell it to say

#209

Earlier quoted context omitted.

> Until a year ago, our passwords are 8 characters max, no special characters, upper and lowercase letters are equal. That’s pretty good. A major Canadian bank until ~2020 had 6 character limit passwords (possibly you could enter more, but only the first six count) and mapped all alpha characters to numbers in groups of 3 (so your assigned telephone banking PIN was just a “hash” of your password). https://news.ycombi…

The best part is when the frontend input and backend validation get out of sync, so your password works sometimes depending on where you come in from.

My health insurance portal (Aetna, no I am not above naming and shaming) did something annoying. When I signed up I used a randomly generated three-word passphrase from my password manager. It was around 32 characters or something.

They have the fun pattern of logging you out of your account whenever you are inactive. A bit excessive for a health insurance provider imo, but whatever.

So I tried to login and guess what? Max input length for their login password is 16 characters. I literally couldn't input my password.

I had to go through a stupid process to reset my password because their sign-up front-end validations were different from their sign-in front-end validations. I had to purposely choose a less secure password even though I could technically create a password that was pretty secure, I can't sign in with it.

Re: Your computer should say what you tell it to say

#210
post #206

Earlier quoted context omitted.

>how does WEI make it _impossible_ for attesters to return higher entropy information? It isn't impossible, but doing so would violate users privacy which isn't the goal of the proposal. You don't need WEI to violate people's privacy. >False, this is an explicit design goal: "Allow web servers to evaluate the authenticity of the device and honest representation of the software stack and the traffic from the device."…

> but WEI is meant to be used in situations where lying should be illegal. But here I once again have to point out that in practice this will look very different. The practical effect is that if someone installs LineageOS or even AOSP to get rid of Google spyware and preinstalled bloatware, then these attestation checks will fail and that user will not be able to use apps that are necessary in practice. The question…

The actual goal is probably that Google and others prevent ad-blocking. WEI itself is not meant as a fingerprint, but with unblockable ads comes unblockable tracking (not that I personally care about tracking). Like, look at YouTube on iPhones, they blocked background playback in the app and even got Apple to block it in Safari in iOS update 10.

They don't need WEI to keep the vast majority of users away from obscure alternative OSes, but as a side effect those would be impacted.

Post reply on HN