Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

91–100 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#91
post #89
post #87

Earlier quoted context omitted.

Came here with roughly the same thought. Given the stated importance to many of sovereignty and not being dependent on the US, why isn’t there more opposition? I assume it’s just ignorance?

There is some opposition, but none of it is making a dent. It's depressing. I can't decide if it's incompetence, corruption, or malice.

Probably some combination of all three.

Re: Hardware Attestation as Monopoly Enabler

#92

It's so obvious to me states need to create a soul bound identity system, replace social security numbers with it, and then let everyone else use cryptography on top of that (which is now cheap when you don't care about sybil attacks) to do private stuff.

The places you actually need an ID are so rare, I don't think it's worth it to build such a system (and no, porn or social network definitely aren't valid use cases). It's a problem in search of a solution.

> It's a problem in search of a solution.

The cynic in me suspects it's a way of slowly but methodically eradicating online anonymity and thus anonymity in general.

Re: Hardware Attestation as Monopoly Enabler

#93
post #66

Earlier quoted context omitted.

So with a single flip of the switch, the president of the USA can shut down our EU Digital Identity Wallet. Why was this decision ever made?

Corruption. A taboo topic people prefer to downvote and pretend it does not exist. But even bigger problem is that institutions designed to prevent this from happening are not doing their job. Thousands security service and civil servants take their wages and look the other way.

No doubt there is corruption; but it’s also momentum. There aren’t stable and good alternatives for so many reasons so the duopoly has momentum

Re: Hardware Attestation as Monopoly Enabler

#94

Earlier quoted context omitted.

If you live in a democracy, you already do run your own country. Vote accordingly. Get involved in politics.

There are mountains of academic research showing that even in “democracies”, public opinion rarely translates into policy (by design).

Even accepting your premise your options are still either:

1) Don't participate (and accept the consequences)

2) Participate (and accept potential disappointment/failure, with the benefit of having tried)

If you view 2) as fruitless unless your desired outcome is likely, you miss the potential value in the pursuit itself: working with like-minded people, building community, developing new skills, taking agency in your own life, and whatever else might come up along the way.

I don't begrudge anyone for choosing 1) (as long as they own their decision and don't force it on others), but 2) still seems like the aspirational choice I'd want to make if I could.

Re: Hardware Attestation as Monopoly Enabler

#96

The thread is a bit vague. Am I understanding correctly that GrapheneOS Foundation's objection isn't to attestation per se, but that they can't participate in Google-controlled attestation APIs? In other words, although GrapheneOS can be cryptographically attested, apps using Google Play Integrity won’t accept it because it isn't Google-certified/GMS-licensed?

My impression is that they are against remote attestation in apps/websites in general and if apps really want to do it, they should do it using the attestation API that AOSP already provides. The attestation API in AOSP allows companies to trust signing key fingerprints (such as those of GrapheneOS), which means that the attestation system is not controlled by a single company (Google). The most damning part about Go…

> very likely to be the most secure mobile OS

> IANAL, but anti-competition lawyers/bodies should have a field day with this, but nobody seems to care

I'm gonna take a wild guess that proving the above statement in court (and then its necessary impact) might be a significant obstacle here?

Re: Hardware Attestation as Monopoly Enabler

#97
post #69

It's so obvious to me states need to create a soul bound identity system, replace social security numbers with it, and then let everyone else use cryptography on top of that (which is now cheap when you don't care about sybil attacks) to do private stuff.

Any system mandated by the government will have a backdoor to deanonymize users. Nothing would convince me otherwise.

Let me try anyway (maybe I'm a masochist)

First I'll say the government already has an ID system with a backdoor they mandate you use (your federal social security ID and state ID). The backdoor isn't very interesting because anyone with your ID in hand also has it.

So how about this:

1. State assigns citizens an ID at birth 2. State allows citizens to submit a public key along with their ID at any time 3. Citizens can go to their bank / private social network / whatever and say "this is my public key, you can use it to sign messages to me, and you can verify someone a) alive and b) a citizen of $state is reading it (from here you can bootstrap whatever protocol you want) 4. The statecitizen network established in (2) is constantly under attack as stealing someones private key valuable so you also need a legal and technical framework to defend it

The protocol for submitting private keys and defending it from attack is a much longer post, I'm convinced there are ways to do it that drastically favor defense over offense, but that's not the point here.

Our question is can a government force it's way into the protocol you bootstrapped on top

How would they?

1. They could reset your public key to one they control the secret to, and then impersonate you digitally to break into your bank or social network. However I don't think they could do this secretly (the key update would necessarily be publically visible), so it's not really a back door. They can already do this with a search warrant. And if you're paranoid you can bootstrap your secondary cryptographic networks with multiple factors. So, this is on net more secure for you.

2. They could try to recover your secret key by force or warrant - but again not a back door.

I think the real concern isn't backdooring it's blacklisting, if this system becomes the L1 for every L2 crytographic interaction, they can practically remove your ability to freely transact. But that's a political problem you address with political means, I'm convinced from a technical perspective this is more secure and far cheaper for everyone.

Re: Hardware Attestation as Monopoly Enabler

#98
Requiring authorized silicon (and software) isn't even the biggest problem here.

They do not use zero knowledge proof systems or blind signatures. So every time you use your device to attest you leave behind something (the attestation packet) that can be used to link the action to your device. They put on a show about how much they care about your privacy by introducing indirection into the process (static device 'ID' is used to acquire an ephemeral 'ID' from an intermediate server) but it's just a show because you don't know what those intermediary severs are doing: You should assume they log everything.

And this just the remote attestation vector, the DRM 'ID' vector is even worse (no meaningful indirection, every license server has access to your burned-in-silicon static identity). And the Google account vector is what it is.

Using blind signatures for remote attestation has actually been proposed, but no one notable is currently using it: https://en.wikipedia.org/wiki/Direct_Anonymous_Attestation>

There are several possible reasons for this, the obvious one is that they want to be able to violate your privacy at will or are mandated to have the capability. The other is that because it's not possible to link an attestation to a particular device the only mitigation to abuse that is feasible is rate limiting which may not be good enough for them - an adversary could set up a farm where every device generates $/hour from providing remote attestations to 'malicious' actors.

Re: Hardware Attestation as Monopoly Enabler

#99
post #21

Earlier quoted context omitted.

> They do not care about you By "they" you mean FAANG and the FTC, right? Telling the EU to respect the Open Web does nothing to protect users if you continue to approve the export of attested hardware. America is deliberately abetting authoritarian schemes.

> By "they" you mean FAANG and the FTC, right? You might need to the sentence again since I was quite clear who I was talking about: "EU government" "banking apps" ...and everyone else who benefits from pushing "digital payments, ID, age verification, etc." that will use "Apple's App Attest and Google's Play Integrity" APIs. It isn't that hard to understand.

There's only two companies enabling those crooks, as far as I can see it. If America refuses to take action, then this power will be abused by worse governments like Russia and China.

Re: Hardware Attestation as Monopoly Enabler

#100
Ironically, the other top article on HN right now is CVE-2024-YIKES.

You can't have the cake and eat it too. Maybe we need to close some doors, especially if the barrier for publication is literally just a couple of prompts and uploading the result to distributor like npm or play store.

Post reply on HN