Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

251–260 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#251

Earlier quoted context omitted.

The EU Commission was caught breaking the law in order to lobby for Chat Control: https://noyb.eu/en/gdpr-complaint-against-x-twitter-over-ill... The EU Commission also gave a foreign tech company called Thorn (they pretend to be a charity), special access to government officials: https://netzpolitik.org/2022/dude-wheres-my-privacy-how-a-ho... I think both of those cases would be examples of lobbying and corruption.

Neither examples are evidence of corruption. That doesn't mean they're not problematic, but there's no evidence here of a politician receiving a kickback for any of these actions.

Corruption does not necessarily mean a politician receiving a kickback. It can be a lot more indirect and subversive.

Re: Hardware Attestation as Monopoly Enabler

#252

Earlier quoted context omitted.

The EU Commission was caught breaking the law in order to lobby for Chat Control: https://noyb.eu/en/gdpr-complaint-against-x-twitter-over-ill... The EU Commission also gave a foreign tech company called Thorn (they pretend to be a charity), special access to government officials: https://netzpolitik.org/2022/dude-wheres-my-privacy-how-a-ho... I think both of those cases would be examples of lobbying and corruption.

Neither examples are evidence of corruption. That doesn't mean they're not problematic, but there's no evidence here of a politician receiving a kickback for any of these actions.

https://fortune.com/europe/2023/09/26/thorn-ashton-kutcher-y...

$600K+ went to kickbacks, er… “lobbying”, and thorn was hit with some pretty nasty scandals involving sex crimes.

Re: Hardware Attestation as Monopoly Enabler

#253

Requiring authorized silicon (and software) isn't even the biggest problem here. They do not use zero knowledge proof systems or blind signatures. So every time you use your device to attest you leave behind something (the attestation packet) that can be used to link the action to your device. They put on a show about how much they care about your privacy by introducing indirection into the process (static device 'ID…

> The other is that because it's not possible to link an attestation to a particular device the only mitigation to abuse that is feasible is rate limiting I still don't see how you can keep something anonymous and still rate limit it. If a service can tell that two requests came from the same party in order to count them then two services can tell that two requests came from the same party (by both pretending to be t…

Just to give an example to prime your intuition: define your "usage token" as H(private_key|service_domain_name|date|4-bit_counter). Make your scheme provably reveal the usage token when you authenticate. Now you can use the service 16 times a day on a particular domain and no more simply by blocking token reuse. And yet the service has no ability to link different tokens to each other or to a specific person because they don't have anyone elses private keys.

You can make variations on this for a wide spectrum of rate limiting behaviors.

But also I agree with xinayder's comment-- the anticompetative, anti-privacy, invasive surveillance is unacceptable. There is a lot of risks with ZKP's that we just make the poison a little less bitter with the end result being more harm to humanity.

I think ZKP systems are intellectually interesting and their lack of use helps make it more clear that the surveillance is really the point of these schemes, not security because most of the security (or more of it) could be achieved without most of the surveillance.

But allowing the apple google duoopoly to control who can read online is wrong even if they did it in a way that better preserved privacy.

And because I can't believe no one else in the thread has linked to it: https://www.gnu.org/philosophy/right-to-read.html

Re: Hardware Attestation as Monopoly Enabler

#254
post #183

Earlier quoted context omitted.

> then you need to receive an attestation from that external dongle, and/or pre-provision it with an identity (like a national ID card.) That's how it works in Germany: You tap your national ID card (as a citizen) or eID card (as a non-citizen) on any NFC-capable iPhone or Android device. I personally much prefer that solution over one that requires a specifically trusted device. The big gap is trusted user confirmat…

The adtechs want this so they can verify the "human" quality of each user. To do this, they don't want people tapping their government ID on their phones every single time they sign up for Reddit or receive an advertisement. Hence (some derivative of) the ID has to be stored on-device to make the browsing/usage experience seamless.

Fair enough, I can see why not.

To me, it seems like just the right amount of friction, and user expectations can work in favor of privacy here: People will hopefully refuse to tap their ID on their phone for a service where they want to remain completely anonymous, even if the protocol technically might support anonymous assertions.

Re: Hardware Attestation as Monopoly Enabler

#255
post #193

Earlier quoted context omitted.

Hell yes. I was going to post the same comment. I don't give a flying fuck how it's implemented. Remote attestation is inherently evil. I remember the WEI apologists trying to do the same thing to derail the argument. The problem is the goal, not the details. Just say no: DO NOT WANT!

Remote attestation is a technology, not a policy or a political effort, so it can't be inherently evil. You can disagree with all its known or proposed uses, but then I think it makes more sense to name these.

"It’s a poor atom blaster that won’t point both ways."

Re: Hardware Attestation as Monopoly Enabler

#256
post #3

Asymmetric cryptography and its consequences have been a disaster for the human race. I’m not even joking all of the centralization of power and the rise of totalitarianism tech is driving is downstream from asymmetric cryptography.

Exactly. The weapon is available to all, but only parasites like FAANG can afford to hire the best brains who know how to wield it. As Apple uses it to take a 30% cut of everything on their device, the “democratized” PGP features in mom’s mail client gather dust.

Re: Hardware Attestation as Monopoly Enabler

#257

Earlier quoted context omitted.

Are there enough of us to run our own country? It makes me feel dumb, but this is a serious question.

Ideally, we just run our own lives, collaboratively. That's the anarchist default position that we all start in. What we really need is to meaningfully participate outside of the hierarchical monopolistic systems that demand our participation. That doesn't just mean that we create and hang out in distributed networks: it also means that we make and do interesting shit there, too. The biggest hurdle I see is that we o…

but what if the alternatives are fundamentally worse? Turns out centralization has a lot of advantages.

I think it's an error to demand the alternatives be as good-- that might not even always be possible. But even if they're less good they're usually still better than anything we could have imagined decades ago-- they're good enough to use.

And that should be enough because we shouldn't consider handing control of ourselves to third parties to be an acceptable choice at all.

Re: Hardware Attestation as Monopoly Enabler

#258
post #6

Our civilization desperately needs a method to modify modern microelectronics after manufacturing that can be used at least in a well-equipped repair shop, and it needs it yesterday. Alternatively, just make it illegal to ship any kind of initial bootloader as part of a CPU's/SoC's mask ROM in any computing device that is marketed as a general-purpose one. I.e. the first instruction that the CPU executes after reset…

Or maybe we should just get rid of the "breaking DRM is illegal"-laws. See https://pluralistic.net/2026/01/01/39c3/

That'll also work somewhat, but the problem would remain that even if it's legal to break the DRM, you can't exactly break it when it's assisted by hardware and there are no vulnerabilities in the "trusted" code.

Re: Hardware Attestation as Monopoly Enabler

#259
post #223

Earlier quoted context omitted.

Local models exist, but there's also irony in using the tools to spread the message of the opposition.

The local models are still centralized and proprietary. They are basically closed source software.

RMS found it acceptable to use SunOS initially to create GNU.

Open weight models can be a big boost to building Open AI (cough). Progress comes from incremental improvements, -- and open weight models are a big advance in privacy, security, and autonomy over relying on hosted closed systems.

Source vs not is only one (important!) dimension, moreover in FSF land they define source as being the preferred form for modification, at at least for some kinds of modifications the weights are the preferred form.

Re: Hardware Attestation as Monopoly Enabler

#260
post #3

Asymmetric cryptography and its consequences have been a disaster for the human race. I’m not even joking all of the centralization of power and the rise of totalitarianism tech is driving is downstream from asymmetric cryptography.

My introduction to asymmetric cryptography had to do with protecting myself from the authorities while buying drugs on the internet. One of its first applications anywhere was protecting anti nuclear protestors from government provocateurs. We could prevent so much fraud of we could only convince the credit card companies to start using it (instead of printing a symmetric secret on the outside of the card). It's pred…

My point is that as far as I understand (not a cryptography expert) once you have the mathematical concept of asymmetric cryptography you also have the mathematical concept of a certificate, so you can't have one without the other.
Post reply on HN