Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

151–160 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#151

The EU Digital (identity) Wallet EUDI requires hardware attestation by Google or Apple, effectively tying all the digital EU identities to American duopoly. Talk about digital sovereignity. Apparently protecting the children > sovereignity. https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...

>To reduce platform dependencies, we also evaluate additional platform independent signal sources. In this context, we evaluate signals from runtime application self-protection (RASP) systems, for example. We also might revisit later whether there are comparable security mechanisms for other platforms. They're basically saying they have no choice but will evaluate better options. So the follow up question is: Are you…

There is the alternative to not to pursue domestic spyware in the fist place. Especially because this is tied to the attempts to deanonymise Internet users.

Re: Hardware Attestation as Monopoly Enabler

#152
> Google's reCAPTCHA is planning an approach where they use Privacy Pass on Apple hardware, their own approach on Google Mobile Services Android devices and a QR code scanning system to require an iOS or Google certified Android device for Windows and other systems

I wonder if we'll get something similar happening with cloudflare

Re: Hardware Attestation as Monopoly Enabler

#154
post #34

Earlier quoted context omitted.

IMO, it would be better if they removed the claim “It doesn't provide a useful security feature” because, even if it does, the collateral damage of making non-Google, non-Apple OSes second class citizens remains, and that is the main problem.

I feel like the complaint about this not adding to security could be read in a really wrong way. Instead of "this is some hypocritical BS", could be interpreted as "lol let's lock EOL devices from even lower integrity tiers". Doubt this is possible because so, so many people use EOL phones, but still.

Doubt this is possible because so, so many people use EOL phones, but still.

Because many people have fortunately realised that "EOL" is just an excuse to create lots of e-waste and push even more hostile unwanted changes.

Re: Hardware Attestation as Monopoly Enabler

#155
post #71
post #66

Earlier quoted context omitted.

So with a single flip of the switch, the president of the USA can shut down our EU Digital Identity Wallet. Why was this decision ever made?

I hate to beat a dead horse and have people downvote me but: the EU has always been corrupted. The knowledge and effects are not evenly distributed until it hits each niche group. Then they find out the hard way that they were useful idiots. It’s ok to be wrong/admit. Let’s just move past the infighting and see those in power for the evil that they are.

The question isn't if there's corruption, the question is who is behind the corruption.

Condescendingly and incorrectly assuming that others think that corruption is impossible is kinda rude and also dodges attempts at correcting the corruption.

Re: Hardware Attestation as Monopoly Enabler

#156

Earlier quoted context omitted.

My impression is that they are against remote attestation in apps/websites in general and if apps really want to do it, they should do it using the attestation API that AOSP already provides. The attestation API in AOSP allows companies to trust signing key fingerprints (such as those of GrapheneOS), which means that the attestation system is not controlled by a single company (Google). The most damning part about Go…

> very likely to be the most secure mobile OS > IANAL, but anti-competition lawyers/bodies should have a field day with this, but nobody seems to care I'm gonna take a wild guess that proving the above statement in court (and then its necessary impact) might be a significant obstacle here?

You don't really "prove" statements like that. You get some "expert witnesses" to testify one way or another, and your opposition gets some "expert witnesses" to testify the opposite, and then the judge/jury decides who they think was more credible.

I imagine the way to do this effectively would be to get some well-regarded infosec firms to audit both OSes (from source as much as possible), and also compile lists of vulnerabilities found, fixed, not-fixed, etc. over time. Then you need a witness who can explain all of it in a way that's accessible to and likely to sway a jury.

Re: Hardware Attestation as Monopoly Enabler

#157
There are a number of technological / legal hybrid policies developing that come at the very jugular vein of computing freedom - the notion of a “general purpose” computer itself. OS level identity / age verification, hardware attestation, walled garden app signature requirements. All evincing the same aim.

Re: Hardware Attestation as Monopoly Enabler

#158
post #66

Earlier quoted context omitted.

So with a single flip of the switch, the president of the USA can shut down our EU Digital Identity Wallet. Why was this decision ever made?

Corruption. A taboo topic people prefer to downvote and pretend it does not exist. But even bigger problem is that institutions designed to prevent this from happening are not doing their job. Thousands security service and civil servants take their wages and look the other way.

Who is doing this corruption?

If it's Apple or Google let us know in the US because we have laws to go after them for acting corruptly in other countries.

Vaguely asserting corruption without specifics or even naming the perpetrators isn't "taboo", it's just poor form and silly. Letting such vague accusations float without evidence, motive, or even people to blame, leads to nothing good, and only vague distrust, which itself enables corruption. It leads to people believing there's no way to know the truth, therefore helplessness, and results in fascism like in Russia.

Lazy cynicism is itself a form of corruption of one's own mind.

Re: Hardware Attestation as Monopoly Enabler

#159
post #90

Earlier quoted context omitted.

I like to ride my bicycle with my friends in rides organized by the (Pacific Northwest) Cascade Bicycle Club. They require that I solve a Google reCAPTCHA in order to register for a ride. Google is already completely locking me out from being able to do that. When I try to click on the squares to select whatever items it's asking, it indefinitely loops. When I try using the audio version, it completely blocks me from…

I hope you contacted them to explain why. People usually think I’m a nut when I do it, or are too stupid to understand and think it’s a tech support issue, but it’s worth at least trying to make it clear that you are choosing not to use/do/pay something because of their choice to use recaptcha

Why not just 2captcha it and go on with your life?

Re: Hardware Attestation as Monopoly Enabler

#160

Requiring authorized silicon (and software) isn't even the biggest problem here. They do not use zero knowledge proof systems or blind signatures. So every time you use your device to attest you leave behind something (the attestation packet) that can be used to link the action to your device. They put on a show about how much they care about your privacy by introducing indirection into the process (static device 'ID…

Can we stop normalizing being surveilled online and on our devices?

Saying something like "the problem is not hardware attestation, but that they don't use ZKP".

You are normalizing the new behavior. You shouldn't. It doesn't matter if they use ZKP or the latest, secure technology for hardware attestation. The issue is hardware attestation. It's the same with age ID. The issue is not that Age ID is prone to data leaks, the problem itself is called Age ID.

Post reply on HN