Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

271–280 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#271
What freedoms do we value ? freedom of speech, freedom of compute, freedom to own assets, to sell our work or give it away, bodily autonomy, freedom to travel, to read to learn ?

Amid the massive hype of the Web3 Crypto era, there was a kernel of useful innovation : that you can choose to have unique digital copies of things, and thus you can have a way of sending value that bypasses the middlemen, be they local thugs, bent politicians, violent regimes, benevolent dictators, or the dominant hegemony.

Having central big-Corp approve your content or sign your executable or take a vig on your sales, or license your hardware - these may be common, but are not a universal law of nature.

The internet itself is our best example of the value of technology open for all to use. Frankly, that is in danger.

Whether it is bogus age-checks in your OS, a hidden bios OS, or the move away from owning your own compute [ because the GPU / CPU and RAM are priced so high you have to rent them ], consumers need to pool resources and ensure open access.

Kudos to France for mandating a Linux OS for their public service workforce. Good on the Europeans for doubling down on renewables to insulate themselves from petrodollar volatility, and making sure portable devices have replaceable batteries.

Cory Doctorow has some great rants on enshizzification. Garys Economics YT channel has some great rants on why high inequality steals resources, see also Piketty.

The technocrats on this forum have an understanding of these measures the common person may not, and thus a moral obligation to weigh in on the issues and warn 'genpop'.

Resist, dont let the buzzkills wear you down.

Re: Hardware Attestation as Monopoly Enabler

#272

Earlier quoted context omitted.

Even if public opinion is unified, if they want something to happen, they are just going to ignore the public and do it anyway. Like the recent cases of data enter projects where they just ignore the public voting against them. Democracy’s weakness it it requires people to follow the rules, but if nobody voluntarily follows the rules, then we don’t really have one.

> Like the recent cases of data enter projects where they just ignore the public voting against them Do you have an example? And was this a binding or non-binding vote?

https://www.tomshardware.com/tech-industry/michigan-towns-ru...

Re: Hardware Attestation as Monopoly Enabler

#273
post #266

Earlier quoted context omitted.

> Why was this decision ever made? because it wasn't made the decision which was made was having a digital ID wallet, that this needs hardware attestation (or something comparable) is somewhat of a direct consequence of existing laws/regulations regarding making IDs forgery safe it also is a phone only application the huge huge majority of phones runs Googled Android/iOS, so you support them if there where a relevant…

Can you show an example of defeating hardware attestation? It would be useful for many 3rd party ROM users.

most times it's done by (reliably re-)rooting a attested phone in a way which bypasses detection of the attestation system

so not really useful for 3rd party ROMs

Re: Hardware Attestation as Monopoly Enabler

#274
It is possible to bypass Play Integrity on most devices (even at the "strong" level) using a sewing needle.

Specifically, you poke the data lines of the memory bus to induce bitflips, much like I described in https://www.da.vidbuchanan.co.uk/blog/dram-emfi.html

This is trickier if your device has the DRAM mounted directly on top of the CPU, but still possible - you'll need to do some BGA rework to get a wire soldered to one of the DQ lines.

Once you get a physical memory read/write primitive, you can start patching the kernel. Play Integrity does not detect this, since it only attests the state of the kernel at boot. I chose to patch out the permission checks related to ptrace, allowing me to inject frida-gadget into running apps, and to inject shellcode into pid 1.

The initial exploit is pretty unreliable, and usually takes a few reboots to hit. But once it lands, the device is pwned until the next reboot - like a "tethered jailbreak".

I tested this on a Samsung A06 because it was the cheapest device supporting Play Integrity I could get my hands on, but there's no fundamental reason it shouldn't work on any other device, including flagships. Some mitigations would require a different exploit strategy (e.g. memory encryption), but the fundamental flaw is still there.

Demo: https://bsky.app/profile/retr0.id/post/3mljtyauw322d

Re: Hardware Attestation as Monopoly Enabler

#275

Earlier quoted context omitted.

> Google et al go to the government and say The money that goes into lobbying in order to have that say is, depending on who you ask, corruption. I, as a random citizen, don't get the same say that a multi billion dollar international corporation does.

That seems like a pretty useless definition of corruption. It implies that retirees writing letters to Congress is "corruption" because working people don't have the same amount of free time to do that. It's also kind of weird to propose it as an asymmetry. Google's parent company spends around $4M on lobbying in the US: https://www.opensecrets.org/federal-lobbying/clients/summary... That's around $0.01 per capita. Y…

The day a low income retiree can have meetings with politicians to lobby for their favorite policies is the day this comparison will be useful.

Re: Hardware Attestation as Monopoly Enabler

#276

Earlier quoted context omitted.

> Why was this decision ever made? because it wasn't made the decision which was made was having a digital ID wallet, that this needs hardware attestation (or something comparable) is somewhat of a direct consequence of existing laws/regulations regarding making IDs forgery safe it also is a phone only application the huge huge majority of phones runs Googled Android/iOS, so you support them if there where a relevant…

Have you seen our President? Minor conveniences are what trigger him into launching full blown DOJ investigations, wars, and economic disaster. If he realizes he can just "turn off" the EU, oh, he will threaten that on Truth Social tonight in a rant about how they should make a deal or else.

[flagged]

Re: Hardware Attestation as Monopoly Enabler

#277

Earlier quoted context omitted.

Protecting the children is their favorite reason for ramping up authoritarian measures.

If they really wanted to protect children, they wouldn't give them phones, tablets, or laptops until a certain age. It's like handing a loaded gun to a kid, and saying "just don't take the safety off". Of course kids are going to find ways around it. They are going to take the safety off.

Australia started on this by banning kids from social media. Reddit kicked up a huge stink and sued the government over it. Also phone bans in school a few years prior.

Re: Hardware Attestation as Monopoly Enabler

#278

Earlier quoted context omitted.

Corruption. A taboo topic people prefer to downvote and pretend it does not exist. But even bigger problem is that institutions designed to prevent this from happening are not doing their job. Thousands security service and civil servants take their wages and look the other way.

I think it's actively harmful to your own cause when you suggest corruption without any evidence. Just because politicians don't take action on an issue you think is important doesn't mean they're corrupt. It's more likely that the issue you think is important is simply not important to most voters. Suggesting politicians are corrupt without any evidence will make that worse. If people think their politicians are cor…

[flagged]

Re: Hardware Attestation as Monopoly Enabler

#279
post #207

In 1999, Intel received an absolutely massive amount of opposition when they decided to include a software-readable serial number in their CPUs, so much that they reversed the decision. Then the "security" and Trusted Computing authoritarians continued pushing for TPMs and related tech, and contributed to the rise of mobile walled gardens. Windows 11's TPM requirements were another step towards their goal. The amount…

Totally with you until you brought in AI, a completely centralized and proprietary tool.

Especially considering AI bots are the whole reason google is pushing this new recaptcha.

Re: Hardware Attestation as Monopoly Enabler

#280
post #267

Earlier quoted context omitted.

> define your "usage token" as H(private_key|service_domain_name|date|4-bit_counter) But how are you preventing multiple services from using the same value for service_domain_name because they're cooperating to correlate your use?

Because-- in this hypothetical-- your user agent restricts the usage to the name displayed on the screen and also because your agent won't send the same value twice either (it'll increment the counter or tell you that its run out of tokens).

Requiring the name to be displayed isn't going to do much for ordinary people. They mostly wouldn't look at it and even if they did, "continue as-is or no service for you" means they continue as-is.

Not sending the same value twice would prevent them from being correlated, but now what are you supposed to do when you run out? Running you out could even be the goal: You burn a token to get a cookie and now you can't clear your cookies or you'll be denied a new one since you're out of tokens.

Post reply on HN