Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

191–200 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#191

The EU Digital (identity) Wallet EUDI requires hardware attestation by Google or Apple, effectively tying all the digital EU identities to American duopoly. Talk about digital sovereignity. Apparently protecting the children > sovereignity. https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...

"protecting" the "children"

Re: Hardware Attestation as Monopoly Enabler

#192

Requiring authorized silicon (and software) isn't even the biggest problem here. They do not use zero knowledge proof systems or blind signatures. So every time you use your device to attest you leave behind something (the attestation packet) that can be used to link the action to your device. They put on a show about how much they care about your privacy by introducing indirection into the process (static device 'ID…

Can we stop normalizing being surveilled online and on our devices? Saying something like "the problem is not hardware attestation, but that they don't use ZKP". You are normalizing the new behavior. You shouldn't. It doesn't matter if they use ZKP or the latest, secure technology for hardware attestation. The issue is hardware attestation. It's the same with age ID. The issue is not that Age ID is prone to data leak…

You're not necessarily being surveiled just because you're forced to authenticate yourself. It often is the case practically, but it's not inherent, and mixing the two up makes the discussion too imprecise in a technical forum.

Hardware attestation often also has problems of centralization, but that's something else as well.

By just labeling it as an abstract bad thing without seeing nuance, I'm afraid you won't be convincing those in power to pass or block these laws, or those convincing your fellow voters which efforts to support.

Re: Hardware Attestation as Monopoly Enabler

#193

Earlier quoted context omitted.

Can we stop normalizing being surveilled online and on our devices? Saying something like "the problem is not hardware attestation, but that they don't use ZKP". You are normalizing the new behavior. You shouldn't. It doesn't matter if they use ZKP or the latest, secure technology for hardware attestation. The issue is hardware attestation. It's the same with age ID. The issue is not that Age ID is prone to data leak…

Hell yes. I was going to post the same comment. I don't give a flying fuck how it's implemented. Remote attestation is inherently evil. I remember the WEI apologists trying to do the same thing to derail the argument. The problem is the goal, not the details. Just say no: DO NOT WANT!

Remote attestation is a technology, not a policy or a political effort, so it can't be inherently evil. You can disagree with all its known or proposed uses, but then I think it makes more sense to name these.

Re: Hardware Attestation as Monopoly Enabler

#194

Earlier quoted context omitted.

The question isn't if there's corruption, the question is who is behind the corruption. Condescendingly and incorrectly assuming that others think that corruption is impossible is kinda rude and also dodges attempts at correcting the corruption.

Not only that, "corruption" is pretty squishy. Let's apply Hanlon's Razor for once. Google et al go to the government and say they've got this attestation thing that can something something security. No one is taking a bribe but also no one they're hearing from is telling them that doing this is going to cement the incumbents. "Security" is good, right? So it makes it into the law. That doesn't meet most formal defin…

[deleted]

Re: Hardware Attestation as Monopoly Enabler

#196

Not to rain on the parade, but doesn't GrapheneOS only works on Google Pixel devices? I mean, that's still in the Google jail on a physical level, even if they swap out the software.

they made a deal with Motorola, from next year we should have an alternative.

in any case, google started to cause issues with pixel 10, so it's not as easy to port it

Re: Hardware Attestation as Monopoly Enabler

#197
post #66

The EU Digital (identity) Wallet EUDI requires hardware attestation by Google or Apple, effectively tying all the digital EU identities to American duopoly. Talk about digital sovereignity. Apparently protecting the children > sovereignity. https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...

So with a single flip of the switch, the president of the USA can shut down our EU Digital Identity Wallet. Why was this decision ever made?

They can also shut down all European payment cards.

Re: Hardware Attestation as Monopoly Enabler

#198
post #87

The EU Digital (identity) Wallet EUDI requires hardware attestation by Google or Apple, effectively tying all the digital EU identities to American duopoly. Talk about digital sovereignity. Apparently protecting the children > sovereignity. https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...

Came here with roughly the same thought. Given the stated importance to many of sovereignty and not being dependent on the US, why isn’t there more opposition? I assume it’s just ignorance?

Since you're so much more informed - which integrity guaranteeing product would you use for mobile devices that European citizens use? Covering more than 90% of population?

Re: Hardware Attestation as Monopoly Enabler

#199
post #76
post #71

Earlier quoted context omitted.

I hate to beat a dead horse and have people downvote me but: the EU has always been corrupted. The knowledge and effects are not evenly distributed until it hits each niche group. Then they find out the hard way that they were useful idiots. It’s ok to be wrong/admit. Let’s just move past the infighting and see those in power for the evil that they are.

Exactly. I have said this for a very long time and the EU (and many other governments) are not our friends and they are just as corrupt. Remember ChatControl? Anytime anyone criticises the EU here, you will get downvoted even after trying to warn the EU defenders that they are not our friends at all. I was asking for evidence about the EU digital ID wallets about what the "disinformation" was around it 3 years ago [0…

> Exactly. I have said this for a very long time and the EU (and many other governments) are not our friends and they are just as corrupt. Remember ChatControl?

The EU parliament shot down ChatControl.

In fact, without the EU, most likely many member states would have ChatControl in some shape. National governments are the ones all in on this crap.

Re: Hardware Attestation as Monopoly Enabler

#200
post #121

Earlier quoted context omitted.

Yea that's fair / makes sense from a democracy point of view (even if I might disagree personally). It's a bit odd that Europe prioritizes American big-business interests I guess? Idk, as an American it does seem kinda like an odd choice.

It's more useful to view the whole situation as EU politicians prioritizing to have their pockets filled with lobbyist money, rather than the EU as a political entity deciding this per se.

It's not completely fair. The US also bullies them into doing those things, it's not only "pure corruption to fill their pockets".

How many European countries buy American weapons because they are scared of what would happen if they pissed off the US? And then they still get tariffs and threats of military invasion.

Post reply on HN