Live data from Hacker News

Your computer should say what you tell it to say

eff.org

251–260 of 263 posts

Re: Your computer should say what you tell it to say

#251

Earlier quoted context omitted.

Can anyone speak to the quality of the shirts? I bought one many years ago at a Linux conference and the design was cool but the shirt itself feels like cardboard and sandpaper, so I never wear it. If the shirts are Bella Canvas or American Life or something else high quality, I'd happily buy some. Tshirts are a great way to raise funds IMHO, and the EFF is doing extremely important work and needs to be funded.

The sizing charts give the shirt manufacturer: https://supporters.eff.org/t-shirt-size-chart#watcheru

Wonderful! Thank you, this is even better than I hoped for :-)

Re: Your computer should say what you tell it to say

#252

Earlier quoted context omitted.

> Yes, because ads are beneficial to the web. Citation needed. Ads are not beneficial to users of the web. There does not exist a website that is better WITH ads. Users do not care about ad fraud. Ads are beneficial to adtech and companies with ad spend. We should not destroy the entire internet to protect/increase adtech profits.

>There does not exist a website that is better WITH ads. Ads can fund the development of the site, the services of the site, and the content on the site. The amount of additional value that the site is able to provide users is much more than the value that gets taken away by including ads. I haven't even mentioned how the ability of users to advertise things on the web is also very useful. >Ads are beneficial to adte…

end users aren't demanding control over the software the ad companies run - maybe that direction would make more sense.

Re: Your computer should say what you tell it to say

#253

Earlier quoted context omitted.

It is totally web-tpm. The differences are irellevant to the essence.

It's far from essence as well. A safe secret storage is not platform attestation.

They are not even merely similar, they are identical.

They are both someone else controlling some part of your property, to control your use of the rest of your property.

Neither is benign or honest. Neither actually does what the sales pitch claims. The sales pitch is a Sales Pitch. It is what you say when you need to convince someone to do something they normally would not want. Anyone can make up a good sounding sales pitch for anything. Quoting the good sounding sales pitch does not show that the thing is good. It just makes one wonder about the speaker.

TPM is not merely "safe secret storage", it's someone else's secret used for someone else's purposes, and one of those purposes is absolutely to "attest" that WEI is valid on this machine at this time.

I can only assume that you know all of this perfectly well and can only guess at possible reasons why anyone who knows what these things do would try to sell the bs cover story that TPM is just another bit of neutral useful handy tech that users can use like a special kind of thumb drive, without mentioning anything about Microsoft and the reality of most actual manufactured devices, and what it actually means even on a machine where it's "disabled".

Re: Your computer should say what you tell it to say

#254

Earlier quoted context omitted.

You'll likely be ushered to their mobile app instead.

I don't do mobile apps. What I'll do instead (and, honestly, this is what I already mostly do anyhow so it's not really a sacrifice) is physically go to the bank branch to conduct my business.

Having visited my local one last summer, and after waiting in line for a good twenty minutes, I wish you luck. Thankfully I can do 99% of what I need through my app/online.

Re: Your computer should say what you tell it to say

#255

I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…

Then we'd better find ways of fooling or defeating WEI. "Tamper proof" indeed. It's just OS DRM. We've cracked DRM, we can crack this.

That sounds like a cat and mouse game that I would rather not play. Look at iOS jailbreaks. They were fairly common early on and still regularly occur. But they are not frequent. Maybe a full jailbreak every year or two. The verifier for WEI can also revoke access to old versions of the software. I don't want to be playing that game to access critical services such as my bank.

Re: Your computer should say what you tell it to say

#256

WEI is a bit like the the old phone system where you were not allowed to own your own phone and connect it to the network. Eventually the government decreed that illegal.

This is the most likely path we'll take, I suspect.

Telephones came about gradually, but say the kind of phone and system roughly like a modern pots line, served up by Bell, started around 1930.

Breakup of ma bell (roughly the same time you were allowed to own a phone) 1984

And even today I can't buy or connect an ONT of my own to the new fiber that Optimum installed a few weeks ago to replace my coax cable and cable modem that I did own (but did not fully control thanks to docsis), somehow.

I am not actually hopeful.

Re: Your computer should say what you tell it to say

#257

Earlier quoted context omitted.

I think the parent posts meant that whoever reviews your banks 2FA should say "that is good" would also look at the SMS system and say "that is good". If they are only doing it to tick compliance boxes then there is probably not much motivation to do it better. Those systems are security theatre.

Yes, I understood what the parent post tried to say, and just wanted to provide a counter example which is not a security theater in its nature. Ah, also the same bank doesn't send SMS anmymore. Everything arrives to their app. Only they fallback to SMS if the app fails to acknowledge receiving the notification, which happens once a year? Also, banks do not mail financial information by default to prevent wiretapping…

How does wiretapping affect mail?

Re: Your computer should say what you tell it to say

#258
post #257

Earlier quoted context omitted.

Yes, I understood what the parent post tried to say, and just wanted to provide a counter example which is not a security theater in its nature. Ah, also the same bank doesn't send SMS anmymore. Everything arrives to their app. Only they fallback to SMS if the app fails to acknowledge receiving the notification, which happens once a year? Also, banks do not mail financial information by default to prevent wiretapping…

How does wiretapping affect mail?

Email, unless you encrypt it yourself, is not encrypted at rest. This means any mail server or relay which your email lands on can be openly mined and analyzed transparently, and without any evidence (which is how GMail works, BTW).

If you're sending sensitive financial information over the mail, it can be read, classified, tied to you and be used against you if required.

So, we have a directive to not email anything financial to the recipient by default.

Re: Your computer should say what you tell it to say

#260

Earlier quoted context omitted.

It's far from essence as well. A safe secret storage is not platform attestation.

They are not even merely similar, they are identical. They are both someone else controlling some part of your property, to control your use of the rest of your property. Neither is benign or honest. Neither actually does what the sales pitch claims. The sales pitch is a Sales Pitch. It is what you say when you need to convince someone to do something they normally would not want. Anyone can make up a good sounding s…

> TPM is not merely "safe secret storage", it's someone else's secret used for someone else's purposes

Not true, you can use it for your secrets as well. There are many many great use-cases for such secret storage.

> one of those purposes is absolutely to "attest" that WEI is valid on this machine at this time.

It can be one of the end results. But that's like blaming CPUs for accelerating crypto with AES-NI.

> They are not even merely similar, they are identical.

If you want to wage an ideological battle, at least remain technically correct.

Post reply on HN