Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

161–170 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#161
In 1999, Intel received an absolutely massive amount of opposition when they decided to include a software-readable serial number in their CPUs, so much that they reversed the decision.

Then the "security" and Trusted Computing authoritarians continued pushing for TPMs and related tech, and contributed to the rise of mobile walled gardens. Windows 11's TPM requirements were another step towards their goal. The amount of propaganda about how that was supposed to be a good thing, both here and elsewhere, was shocking.

It turns out a significant (but hopefully decreasing) number of the population is easily coerced into anything when "security" is given as a justification.

The war on general-purpose computing continues, and we need to keep fighting.

Stallman was right, as always. Time to give his "Right to Read" another read. (If it hasn't been done already, an AI-generated short film of it would be a great idea...)

"Those who give up freedom for security deserve neither."

Re: Hardware Attestation as Monopoly Enabler

#162
post #39

Earlier quoted context omitted.

There's a thread awhile back where there were VERY angry at someone trying to setup their own attestation project database (essentially a list of known Android builds and their signatures). They want apps to add their signing hashes manually just for them and don't want to join projects that would aggregate and act as a database or certificate authority.

You mean Universal Attestation, which is from a vendor cartel, of which most of the individual vendors are typically waaaaay behind security updates, etc.

No, it wasn't those. It was another EU org.

Re: Hardware Attestation as Monopoly Enabler

#163
post #71

Earlier quoted context omitted.

I hate to beat a dead horse and have people downvote me but: the EU has always been corrupted. The knowledge and effects are not evenly distributed until it hits each niche group. Then they find out the hard way that they were useful idiots. It’s ok to be wrong/admit. Let’s just move past the infighting and see those in power for the evil that they are.

The question isn't if there's corruption, the question is who is behind the corruption. Condescendingly and incorrectly assuming that others think that corruption is impossible is kinda rude and also dodges attempts at correcting the corruption.

Not only that, "corruption" is pretty squishy. Let's apply Hanlon's Razor for once.

Google et al go to the government and say they've got this attestation thing that can something something security. No one is taking a bribe but also no one they're hearing from is telling them that doing this is going to cement the incumbents. "Security" is good, right? So it makes it into the law.

That doesn't meet most formal definitions of corruption. It's more like incompetence than malice. But the outcome is indistinguishable from corruption. The bad thing gets into the law.

The difference is, if the politicians are taking bribes and you get mad at them, they fob you off because they're more interested in lining their pockets. But if the politicians are just misinformed bureaucrats and you get mad at them, they might actually fix it.

And attributing everything to "corruption" discourages people from doing the latter even in cases where it would be effective.

Re: Hardware Attestation as Monopoly Enabler

#164
post #152

> Google's reCAPTCHA is planning an approach where they use Privacy Pass on Apple hardware, their own approach on Google Mobile Services Android devices and a QR code scanning system to require an iOS or Google certified Android device for Windows and other systems I wonder if we'll get something similar happening with cloudflare

If you use Turnstile you can skip all the Cloudflare captchas.

Re: Hardware Attestation as Monopoly Enabler

#165

Requiring authorized silicon (and software) isn't even the biggest problem here. They do not use zero knowledge proof systems or blind signatures. So every time you use your device to attest you leave behind something (the attestation packet) that can be used to link the action to your device. They put on a show about how much they care about your privacy by introducing indirection into the process (static device 'ID…

Can we stop normalizing being surveilled online and on our devices? Saying something like "the problem is not hardware attestation, but that they don't use ZKP". You are normalizing the new behavior. You shouldn't. It doesn't matter if they use ZKP or the latest, secure technology for hardware attestation. The issue is hardware attestation. It's the same with age ID. The issue is not that Age ID is prone to data leak…

Hell yes. I was going to post the same comment. I don't give a flying fuck how it's implemented. Remote attestation is inherently evil.

I remember the WEI apologists trying to do the same thing to derail the argument. The problem is the goal, not the details. Just say no: DO NOT WANT!

Re: Hardware Attestation as Monopoly Enabler

#166

The EU Digital (identity) Wallet EUDI requires hardware attestation by Google or Apple, effectively tying all the digital EU identities to American duopoly. Talk about digital sovereignity. Apparently protecting the children > sovereignity. https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...

One of the major problems with on-device identifiers is that they must by tied tightly to devices, due to the risks of cloning. This is particularly true for privacy-preserving identifiers. That's why device attestation is so important, because you can't ensure that identity (keys) are locked to a device unless you can verify that the hardware prevents users from extracting keys. The worst part of this is that motivated criminals will certainly figure out how to extract those keys and use them for fraud; it's open-source and open computing that will be destroyed by this.

Re: Hardware Attestation as Monopoly Enabler

#167

With all of the discourse around hardware attestation, digital ID, and age verification in recent weeks/months, is there actually any good solution to the problems these existing tools (Privacy Pass, WEI, Fraud Defense, uploading IDs) claim to solve? Are there open and privacy-preserving standards that can solve the problem of bots and minors? If not, what would be required to establish one, and is it realistic? Busi…

> Are there open and privacy-preserving standards that can solve the problem of bots and minors? If not, what would be required to establish one, and is it realistic?

Ideally there shouldn't be standards for this. What we have already is enough.

Companies claiming they are closing down their services/devices to protect the users is total BS. Facebook has admitted they get 10% of their ad revenue from scams, and that's the reason they won't go after scammers on their platforms.

Same can be said for Google. They could come up with numerous ways to block bots or make captchas harder for actual bots (while also not flagging every non-Chrome user as a potential bot, like they do nowadays), but they pretend this is an unsolvable problem that requires a nuclear solution, it used to be Web DRM but now it's called Fraud Defense.

Re: Hardware Attestation as Monopoly Enabler

#168
post #66

Earlier quoted context omitted.

So with a single flip of the switch, the president of the USA can shut down our EU Digital Identity Wallet. Why was this decision ever made?

Corruption. A taboo topic people prefer to downvote and pretend it does not exist. But even bigger problem is that institutions designed to prevent this from happening are not doing their job. Thousands security service and civil servants take their wages and look the other way.

It's more of a case of the boy who cried wolf than it is of denial.

Too many people see something they don't like, imply a nefarious motivation without evidence, then expect everyone to agree that it is corruption.

If there is corruption, show the evidence. Otherwise, be honest and state that you don't agree with something. If you want to persuade people, back up your claims with verifiable evidence without falling back to nebulous claims of corruption.

Re: Hardware Attestation as Monopoly Enabler

#169

The EU Digital (identity) Wallet EUDI requires hardware attestation by Google or Apple, effectively tying all the digital EU identities to American duopoly. Talk about digital sovereignity. Apparently protecting the children > sovereignity. https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...

> Apparently protecting the children trumps sovereignity.

Capital remains sovereign in Europe.

Re: Hardware Attestation as Monopoly Enabler

#170

Earlier quoted context omitted.

you know that domestic capability means putting taxes to take things into a public good and corporations and paranoia are the bigger problem to overcome than anything technical. Any endevour will be cast as some kind of fascist takeover of governance.

Well no, there is no need to develop domestic capability. Put laws in effect which disable foreign capabilities and which reward domestic ones, and they will be developed. No endeavor from government needed (which is a good thing, since governments are not really great at doing such stuff).

Well yes, just because you think it's a public good worth competing over doesn't mean there's anyone who thinks it's a viable business model.
Post reply on HN