Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

241–250 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#241

Earlier quoted context omitted.

> The other is that because it's not possible to link an attestation to a particular device the only mitigation to abuse that is feasible is rate limiting I still don't see how you can keep something anonymous and still rate limit it. If a service can tell that two requests came from the same party in order to count them then two services can tell that two requests came from the same party (by both pretending to be t…

The way it would work with blind signatures is that the server will know the device that comes to it to request a blinded signature and will be able to rate limit how often that device asks it. But once you get the response you can unblind the signed signature and obtain the token (which is just the unblinded signature). This token can then be used once either because its blacklisted after use (and it expires before…

> But once you get the response you can unblind the signed signature and obtain the token (which is just the unblinded signature).

The premise of this is to keep the person issuing the tokens and the person accepting them from correlating you.

The issue is when you have more than one service accepting them. You go to use Facebook and WhatsApp but they're both Meta so you present the same unblinded signature to both services and now your Facebook and WhatsApp accounts are correlated against your will. And they have a network that does the same thing, so you go to use a third party service and they require you to submit your unblinded signature to Meta which allows them to correlate you everywhere.

Re: Hardware Attestation as Monopoly Enabler

#242

The EU Digital (identity) Wallet EUDI requires hardware attestation by Google or Apple, effectively tying all the digital EU identities to American duopoly. Talk about digital sovereignity. Apparently protecting the children > sovereignity. https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...

Protecting the children is their favorite reason for ramping up authoritarian measures.

If they really wanted to protect children, they wouldn't give them phones, tablets, or laptops until a certain age.

It's like handing a loaded gun to a kid, and saying "just don't take the safety off".

Of course kids are going to find ways around it. They are going to take the safety off.

Re: Hardware Attestation as Monopoly Enabler

#243

Earlier quoted context omitted.

They can also shut down all European payment cards.

Maybe not all of them, but certainly a few large, popular ones. You bring up a good point though, it seems surprising that Wero/PEPSI don't have more momentum. Maybe Europeans hate their continental neighbors more than American financial conglomerates.

The EU might have slept on Russia having to urgently come up with its own payment systems after the 2014 Crimea annexation (which in turn enabled it to deal with the complete Visa/Mastercard exit in 2022) because political goals were aligned and transatlanticism was still alive and well. But they've been wide awake ever since ICC employees have been personally sanctioned by the US as well [1].

Big ships turn slowly, but I give it at most two more years until at least one pan-European retail payment scheme (cards, QR, or maybe the "digital Euro") has been regulated into existence.

[1] https://www.theguardian.com/law/2026/feb/18/international-cr...

Re: Hardware Attestation as Monopoly Enabler

#244
post #66

The EU Digital (identity) Wallet EUDI requires hardware attestation by Google or Apple, effectively tying all the digital EU identities to American duopoly. Talk about digital sovereignity. Apparently protecting the children > sovereignity. https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...

So with a single flip of the switch, the president of the USA can shut down our EU Digital Identity Wallet. Why was this decision ever made?

We (America) made the decision for them. The EU's member states were either:

1. Explicitly designed as client states for the US

2. Explicitly designed as client states for the Soviet Union, with alliances switching over as the Soviet Union fell apart

3. Great Britain, a country whose electorate would probably only reconsider rejoining if the EU agreed to explicitly become British client states, because the only thing Britain hates more than France is those dastardly American upstarts[0].

The reason why this persists despite an openly hostile American president is the fact that the EU has no real alternative. The EU has a shitton of internal political distrust between member states, and the US was offering a lubricating alternative: "Just trust us." Politically distributed alternatives require balancing coalitions that are far more fragile.

[0] The history of European anti-Americanism is extremely fascinating, because it's effectively a Reactionary meme - as in, "wanting to restore the Ancien Regime" Reactionary, not "funny way to say Nazi Party member" Reactionary. And yet it's jumped across so many incompatible political ideologies that the average European probably had no clue why they hate America until Donald Trump gave them a good reason to.

Re: Hardware Attestation as Monopoly Enabler

#245

Earlier quoted context omitted.

Can we stop normalizing being surveilled online and on our devices? Saying something like "the problem is not hardware attestation, but that they don't use ZKP". You are normalizing the new behavior. You shouldn't. It doesn't matter if they use ZKP or the latest, secure technology for hardware attestation. The issue is hardware attestation. It's the same with age ID. The issue is not that Age ID is prone to data leak…

Hell yes. I was going to post the same comment. I don't give a flying fuck how it's implemented. Remote attestation is inherently evil. I remember the WEI apologists trying to do the same thing to derail the argument. The problem is the goal, not the details. Just say no: DO NOT WANT!

The biggest problem is banking system. "Don't want - no bank for you". That's the problem.

Re: Hardware Attestation as Monopoly Enabler

#246

Earlier quoted context omitted.

Not only that, "corruption" is pretty squishy. Let's apply Hanlon's Razor for once. Google et al go to the government and say they've got this attestation thing that can something something security. No one is taking a bribe but also no one they're hearing from is telling them that doing this is going to cement the incumbents. "Security" is good, right? So it makes it into the law. That doesn't meet most formal defin…

> Google et al go to the government and say The money that goes into lobbying in order to have that say is, depending on who you ask, corruption. I, as a random citizen, don't get the same say that a multi billion dollar international corporation does.

That seems like a pretty useless definition of corruption. It implies that retirees writing letters to Congress is "corruption" because working people don't have the same amount of free time to do that.

It's also kind of weird to propose it as an asymmetry. Google's parent company spends around $4M on lobbying in the US:

https://www.opensecrets.org/federal-lobbying/clients/summary...

That's around $0.01 per capita. Your per capita contribution for individuals to out-spend Google on lobbying is two cents.

Re: Hardware Attestation as Monopoly Enabler

#247

Earlier quoted context omitted.

Are there enough of us to run our own country? It makes me feel dumb, but this is a serious question.

If you live in a democracy, you already do run your own country. Vote accordingly. Get involved in politics.

When one group says “we don’t want surveillance” and the other group says “we will use surveillance to destroy you” the equilibrium is clear. This is why liberalism will not survive in the 21st century.

Re: Hardware Attestation as Monopoly Enabler

#248
post #192

Earlier quoted context omitted.

Can we stop normalizing being surveilled online and on our devices? Saying something like "the problem is not hardware attestation, but that they don't use ZKP". You are normalizing the new behavior. You shouldn't. It doesn't matter if they use ZKP or the latest, secure technology for hardware attestation. The issue is hardware attestation. It's the same with age ID. The issue is not that Age ID is prone to data leak…

You're not necessarily being surveiled just because you're forced to authenticate yourself. It often is the case practically, but it's not inherent, and mixing the two up makes the discussion too imprecise in a technical forum. Hardware attestation often also has problems of centralization, but that's something else as well. By just labeling it as an abstract bad thing without seeing nuance, I'm afraid you won't be c…

> You're not necessarily being surveiled just because you're forced to authenticate yourself.

Oh hell you do! Google profit comes from ADS! It's for their profit to surveil and track and deanonymize TO SELL ADS.

Re: Hardware Attestation as Monopoly Enabler

#249

Earlier quoted context omitted.

The way it would work with blind signatures is that the server will know the device that comes to it to request a blinded signature and will be able to rate limit how often that device asks it. But once you get the response you can unblind the signed signature and obtain the token (which is just the unblinded signature). This token can then be used once either because its blacklisted after use (and it expires before…

> But once you get the response you can unblind the signed signature and obtain the token (which is just the unblinded signature). The premise of this is to keep the person issuing the tokens and the person accepting them from correlating you. The issue is when you have more than one service accepting them. You go to use Facebook and WhatsApp but they're both Meta so you present the same unblinded signature to both s…

> you present the same unblinded signature to both services

You would never do this as it defeats the entire purpose of using blind signatures to begin with.

Re: Hardware Attestation as Monopoly Enabler

#250

Earlier quoted context omitted.

The question isn't if there's corruption, the question is who is behind the corruption. Condescendingly and incorrectly assuming that others think that corruption is impossible is kinda rude and also dodges attempts at correcting the corruption.

Not only that, "corruption" is pretty squishy. Let's apply Hanlon's Razor for once. Google et al go to the government and say they've got this attestation thing that can something something security. No one is taking a bribe but also no one they're hearing from is telling them that doing this is going to cement the incumbents. "Security" is good, right? So it makes it into the law. That doesn't meet most formal defin…

Anything involving trust cements the incumbents or at least creates a force to an outcome of few players. It is what it is.

It's not a given that it's incompetence.

Post reply on HN