Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

131–140 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#131
post #76
post #71

Earlier quoted context omitted.

I hate to beat a dead horse and have people downvote me but: the EU has always been corrupted. The knowledge and effects are not evenly distributed until it hits each niche group. Then they find out the hard way that they were useful idiots. It’s ok to be wrong/admit. Let’s just move past the infighting and see those in power for the evil that they are.

Exactly. I have said this for a very long time and the EU (and many other governments) are not our friends and they are just as corrupt. Remember ChatControl? Anytime anyone criticises the EU here, you will get downvoted even after trying to warn the EU defenders that they are not our friends at all. I was asking for evidence about the EU digital ID wallets about what the "disinformation" was around it 3 years ago [0…

> Remember ChatControl?

That thing that got refused multiple times already?

Because not all politicians think like you does not mean they are corrupt. Seems like enough politicians have voted against ChatControl until now.

I always wonder what people who say stuff like "politicians discussed this topic I hate and refused it, but the mere fact that they discussed means that they must all be corrupt" understand about politics. You know that it is about people with different opinions (representing people with different opinions) discussing stuff, right?

Re: Hardware Attestation as Monopoly Enabler

#132
post #6

Our civilization desperately needs a method to modify modern microelectronics after manufacturing that can be used at least in a well-equipped repair shop, and it needs it yesterday. Alternatively, just make it illegal to ship any kind of initial bootloader as part of a CPU's/SoC's mask ROM in any computing device that is marketed as a general-purpose one. I.e. the first instruction that the CPU executes after reset…

TFA is authored by the developers of an alternative operating system that can be freely installed on every Google phone since Pixel 6.

Re: Hardware Attestation as Monopoly Enabler

#133
post #76
post #71

Earlier quoted context omitted.

I hate to beat a dead horse and have people downvote me but: the EU has always been corrupted. The knowledge and effects are not evenly distributed until it hits each niche group. Then they find out the hard way that they were useful idiots. It’s ok to be wrong/admit. Let’s just move past the infighting and see those in power for the evil that they are.

Exactly. I have said this for a very long time and the EU (and many other governments) are not our friends and they are just as corrupt. Remember ChatControl? Anytime anyone criticises the EU here, you will get downvoted even after trying to warn the EU defenders that they are not our friends at all. I was asking for evidence about the EU digital ID wallets about what the "disinformation" was around it 3 years ago [0…

(ignorant) people proposing things does not mean corruption: the fact that these things are voted down and never pass is proof that the system works, not evidence of corruption.

Corruption would be if it passed despite it being unpopular, because some corporate or rich peoples interests desired it.

Re: Hardware Attestation as Monopoly Enabler

#134
post #81

The EU Digital (identity) Wallet EUDI requires hardware attestation by Google or Apple, effectively tying all the digital EU identities to American duopoly. Talk about digital sovereignity. Apparently protecting the children > sovereignity. https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...

I wrote to the EU contact about this, got a patronising reply about how good it is, app being open source and what not. Clearly tailored to the regular normie without technical skills.

Where did you write? Is there a link or something you could share? I am not in the EU so I assume I can't, but would be nice to share a link so that other EU citizen could write.

If enough people write, they may start finding it relevant.

Re: Hardware Attestation as Monopoly Enabler

#135
> It doesn't provide a useful security feature, but it does lock out competition very well.

This seems to presuppose that service providers using reCAPTCHA are either clueless idiots or actively expending resources and lowering their conversion rates to support the supposed Google/Apple duopoly. That does not strike me as a plausible claim.

Re: Hardware Attestation as Monopoly Enabler

#136
post #81

Earlier quoted context omitted.

I wrote to the EU contact about this, got a patronising reply about how good it is, app being open source and what not. Clearly tailored to the regular normie without technical skills.

Probably because the reply was written by someone without technical skills. I’ve written to politicians over the years about technical matters and it’s uniformly either a clearly form response or an inaccurate summation of the technical risks, if I’m been charitable because they don’t understand them either. At a certain point it begins to feel pointless.

> At a certain point it begins to feel pointless.

I think you're right that they are incompetent. The point is not to make them understand it, but rather to make them see that enough people care. The problem is that most people don't write, so the politicians don't see that they care. Same thing for companies. How many GrapheneOS users say "well when it stops working, I just move to another service, and if there is none, then I live without the service entirely". That way the companies never see that there is a need.

Re: Hardware Attestation as Monopoly Enabler

#137
post #66

Earlier quoted context omitted.

So with a single flip of the switch, the president of the USA can shut down our EU Digital Identity Wallet. Why was this decision ever made?

Corruption. A taboo topic people prefer to downvote and pretend it does not exist. But even bigger problem is that institutions designed to prevent this from happening are not doing their job. Thousands security service and civil servants take their wages and look the other way.

The EU does regulate Google and Apple through the DSA and the DMA. I don't think most EU politicians are corrupted by these companies.

I think it is far more likely that it is a lack of knowledge and incompetence. I am pretty sure that the majority of Parliament members, Council members and maybe even Commission members do not even know that there are viable alternatives outside Google (certified) Android and iOS. So they try to regulate their app stores, etc. instead.

I hope that with digital sovereignty becoming more important, there will be more interer in alternative mobile operating systems.

Re: Hardware Attestation as Monopoly Enabler

#138
post #89
post #87

Earlier quoted context omitted.

Came here with roughly the same thought. Given the stated importance to many of sovereignty and not being dependent on the US, why isn’t there more opposition? I assume it’s just ignorance?

There is some opposition, but none of it is making a dent. It's depressing. I can't decide if it's incompetence, corruption, or malice.

Before thinking about corruption or malice, I like to try to assume good faith. And I see a couple things:

1. Most people don't write.

2. The people who write are not always competent.

3. The people who write often have an agenda, too.

What's the consequence of that? Imagine what the politicians receive: tons of messages of people complaining, most of which are factually wrong. What to do then? How to know who is right? It's genuinely hard.

EDIT: please write here: https://european-union.europa.eu/contact-eu/write-us_en

Re: Hardware Attestation as Monopoly Enabler

#139
post #66

Earlier quoted context omitted.

So with a single flip of the switch, the president of the USA can shut down our EU Digital Identity Wallet. Why was this decision ever made?

Corruption. A taboo topic people prefer to downvote and pretend it does not exist. But even bigger problem is that institutions designed to prevent this from happening are not doing their job. Thousands security service and civil servants take their wages and look the other way.

I think it's actively harmful to your own cause when you suggest corruption without any evidence. Just because politicians don't take action on an issue you think is important doesn't mean they're corrupt. It's more likely that the issue you think is important is simply not important to most voters.

Suggesting politicians are corrupt without any evidence will make that worse. If people think their politicians are corrupt they will further disengage with the political process, which will ensure there's even less pressure on politicians to take action on niche issues like this.

Re: Hardware Attestation as Monopoly Enabler

#140

Earlier quoted context omitted.

> …Google could trivially make it work with GrapheneOS (which is more secure than any other Android OS on the market) but they won't. But if Google did support third-party attestation, would the GrapheneOS Foundation be happy? Most of the thread seems to be a call for attestation to die, which feels impractical and unachievable. But "Google could use it to permit GrapheneOS for Play Integrity if that was actually abo…

Why should Google decide which devices are safe enough to pass remote attestation? Seems to me that if we want this at all, it should be an independent body that approves signing keys of vetted vendors (e.g. vendors roll out security updates timely, etc.). As long as this is in Google's hands, they can abuse it to control the market. That said, Play Integrity accepting GrapheneOS would be a step forward, but they wil…

Then you’re just replacing one DRM cartel with another.

What would even be the criteria for approval? Pinky promise to not let the end user have full control of their own device? That’s all “integrity” really means in practice. Don’t be fooled by appeals to security.

Post reply on HN