Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

171–180 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#171

The EU Digital (identity) Wallet EUDI requires hardware attestation by Google or Apple, effectively tying all the digital EU identities to American duopoly. Talk about digital sovereignity. Apparently protecting the children > sovereignity. https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...

One of the major problems with on-device identifiers is that they must by tied tightly to devices, due to the risks of cloning. This is particularly true for privacy-preserving identifiers. That's why device attestation is so important, because you can't ensure that identity (keys) are locked to a device unless you can verify that the hardware prevents users from extracting keys. The worst part of this is that motiva…

Only if you need to have the entire application behavior (or at least some trusted confirmation) attested, right? Otherwise, an external USB dongle, tapping a contactless smartcard on a phone etc. could do just fine.

Re: Hardware Attestation as Monopoly Enabler

#172

Earlier quoted context omitted.

>To reduce platform dependencies, we also evaluate additional platform independent signal sources. In this context, we evaluate signals from runtime application self-protection (RASP) systems, for example. We also might revisit later whether there are comparable security mechanisms for other platforms. They're basically saying they have no choice but will evaluate better options. So the follow up question is: Are you…

There is the alternative to not to pursue domestic spyware in the fist place. Especially because this is tied to the attempts to deanonymise Internet users.

It's also an attempt to keep various malefactors such as America, Russia, Israel, China, etc out off the propaganda efforts driving a large amount of far right nationalists into violent uprising.

Re: Hardware Attestation as Monopoly Enabler

#174

The EU Digital (identity) Wallet EUDI requires hardware attestation by Google or Apple, effectively tying all the digital EU identities to American duopoly. Talk about digital sovereignity. Apparently protecting the children > sovereignity. https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...

You want a secure identity? ISO7816 exists and is completely independent of Big Tech. The question of who should be required to show ID is different (and I'd argue the answer is "no" in most online-only situations), but there's already a solution that's been trusted by the financial sector for decades.

Re: Hardware Attestation as Monopoly Enabler

#175

Requiring authorized silicon (and software) isn't even the biggest problem here. They do not use zero knowledge proof systems or blind signatures. So every time you use your device to attest you leave behind something (the attestation packet) that can be used to link the action to your device. They put on a show about how much they care about your privacy by introducing indirection into the process (static device 'ID…

Can we stop normalizing being surveilled online and on our devices? Saying something like "the problem is not hardware attestation, but that they don't use ZKP". You are normalizing the new behavior. You shouldn't. It doesn't matter if they use ZKP or the latest, secure technology for hardware attestation. The issue is hardware attestation. It's the same with age ID. The issue is not that Age ID is prone to data leak…

There is a problem where it's becoming increasingly harder to determine which internet packets that are coming to your service are at the behest of a human in the course of normal activities or an automated program.

If all the internet was is static content, that wouldn't be much of a problem. But we live in world where packets coming to your service result in significant state changes to your database (such as user generated content).

I suspect that we are currently in the valley of do-something-about-it on the graph which is why you see all this angst from the big players. Would Google really care if automated programs were so good that they were approximating real humans to such an extent that absolutely no one can tell? I suspect they would not only be happy with such a state of affairs, they would join in.

Re: Hardware Attestation as Monopoly Enabler

#176

Earlier quoted context omitted.

Can we stop normalizing being surveilled online and on our devices? Saying something like "the problem is not hardware attestation, but that they don't use ZKP". You are normalizing the new behavior. You shouldn't. It doesn't matter if they use ZKP or the latest, secure technology for hardware attestation. The issue is hardware attestation. It's the same with age ID. The issue is not that Age ID is prone to data leak…

There is a problem where it's becoming increasingly harder to determine which internet packets that are coming to your service are at the behest of a human in the course of normal activities or an automated program. If all the internet was is static content, that wouldn't be much of a problem. But we live in world where packets coming to your service result in significant state changes to your database (such as user…

That's not a problem at all. It's an artificially created distraction, created to manufacture consent, by those pushing for this shit.

Re: Hardware Attestation as Monopoly Enabler

#177
post #171

Earlier quoted context omitted.

One of the major problems with on-device identifiers is that they must by tied tightly to devices, due to the risks of cloning. This is particularly true for privacy-preserving identifiers. That's why device attestation is so important, because you can't ensure that identity (keys) are locked to a device unless you can verify that the hardware prevents users from extracting keys. The worst part of this is that motiva…

Only if you need to have the entire application behavior (or at least some trusted confirmation) attested, right? Otherwise, an external USB dongle, tapping a contactless smartcard on a phone etc. could do just fine.

Sure, but then you need to receive an attestation from that external dongle, and/or pre-provision it with an identity (like a national ID smartcard.) It might work in places that distribute this hardware, but it's a crummy UX. I expect that the goal of these systems is to make ID verification a requirement for most routine device usage, sadly, and external dongles will crap that up from a UX perspective.

There is also the problem that most external hardware is less secure than things like Apple's SEP. (But on the other hand, probably more secure than the long tail of cheap Android phones, which use virtualization rather than real hardware.)

Re: Hardware Attestation as Monopoly Enabler

#178

Requiring authorized silicon (and software) isn't even the biggest problem here. They do not use zero knowledge proof systems or blind signatures. So every time you use your device to attest you leave behind something (the attestation packet) that can be used to link the action to your device. They put on a show about how much they care about your privacy by introducing indirection into the process (static device 'ID…

> The other is that because it's not possible to link an attestation to a particular device the only mitigation to abuse that is feasible is rate limiting

I still don't see how you can keep something anonymous and still rate limit it. If a service can tell that two requests came from the same party in order to count them then two services can tell that two requests came from the same party (by both pretending to be the same service) and therefore correlate them.

Re: Hardware Attestation as Monopoly Enabler

#179
post #131

Earlier quoted context omitted.

> Remember ChatControl? That thing that got refused multiple times already? Because not all politicians think like you does not mean they are corrupt. Seems like enough politicians have voted against ChatControl until now. I always wonder what people who say stuff like "politicians discussed this topic I hate and refused it, but the mere fact that they discussed means that they must all be corrupt" understand about p…

The Commission got it through on the last round, though, so eventually it passed.

So ChatControl was accepted and is in the process of being implemented is what you say?

Re: Hardware Attestation as Monopoly Enabler

#180

The EU Digital (identity) Wallet EUDI requires hardware attestation by Google or Apple, effectively tying all the digital EU identities to American duopoly. Talk about digital sovereignity. Apparently protecting the children > sovereignity. https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...

The EU problem here is they are simply reactive, and slow at it. By ceding the active part of commercialized innovation to the US (because paying the people that do such things what they're worth is simply incomprehensible) they allow them to dictate the terms of engagement. The utter dependence on WhatsApp being a shining example, as well as cloud services in general.

If anyone wants to assert control they have to be where the puck is going instead.

Post reply on HN