Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

301–310 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#301
post #300

Earlier quoted context omitted.

It's also an attempt to keep various malefactors such as America, Russia, Israel, China, etc out off the propaganda efforts driving a large amount of far right nationalists into violent uprising.

Yes, comrade, those newsletters should be disposed because of evil foreign pяopoganda

I'm zorry, have you slept through brexit, january 6th, racist anti immigration campaigns and torture prisons?

Are you just not paying attention to the dissolution of democracy or are youjust like, cool with money being the only protected thing.

Re: Hardware Attestation as Monopoly Enabler

#302

I am reminded of the period when secure boot was being developed for PCs. Microsoft certainly wanted to be the only company whose OS was allowed to boot with secure boot turned on. Google should not be allowed to close the supposedly "open" ecosystem they created any more than Microsoft was allowed to.

> the period when secure boot was being developed for PCs.

You mean right now? At a firmware level, the scope of "trusted computing" is expanding with every passing year.

> close the ecosystem they created any more than Microsoft was allowed to.

We are in the process of allowing Microsoft to close the PC platform. TPM is required to run Windows now. Nearly every new PC ships with "secure boot" enabled, adding a new technical barrier to escaping Windows that didn't exist before. Remove that toggle from the BIOS, and you now effectively have a vehicle to Windows-only PCs.

Re: Hardware Attestation as Monopoly Enabler

#303

Earlier quoted context omitted.

As usual, the story is much more nuanced and complicated than the simplistic and convenient narrative of "ignoring the public." And reading diluted blogspam like Tom's Hardware doesn't help. Here is the full story: (Source: https://archive.ph/Kiyn9 ) > The commission rejected the plan to rezone the farmland [that would allow the data center to be built]. The township board followed suit, voting 4–1 to deny it. But lo…

So a vote happened, and when it didn’t go their way, huge company threatened a huge lawsuit that the township and citizens couldn’t afford, to get their way anyway. Standard corporate bullying tactic in America. The story perfectly exemplifies how little democratic control the public has over what corporations do in and do to their community.

The reason the would-be purchaser sued the state is that they had a plausible argument that the township's denial was illegal under Michigan state law. There are quotes in the article from the Governor's office that they support the construction of data centers. This isn't democracy not working; it's that the efforts need to go up to the state level in the hierarchy.

Re: Hardware Attestation as Monopoly Enabler

#304
It seems to me that comments here are reading this as saying attestation is bad, when the real argument is that attestation should explicitly provide a path of inclusion for non-Apple and Google providers.

The headline seems to make the statement that Apple and Google are evil and doing this for monopoly lock-in, and GrapheneOS, a competitor, will stand for the people against that. But given their final counterpoint is that they should have been included too and they rant about being rejected from Google's Play Integrity API for unclear reasons they claim are malicious, it seems they do acknowledge there's security value here: we do critically need for full-chain-of-signature attestations for critical identity data, the only way to avoid someone using AI to create fraud identities trivially.

Re: Hardware Attestation as Monopoly Enabler

#306

Earlier quoted context omitted.

Corruption. A taboo topic people prefer to downvote and pretend it does not exist. But even bigger problem is that institutions designed to prevent this from happening are not doing their job. Thousands security service and civil servants take their wages and look the other way.

Who is doing this corruption? If it's Apple or Google let us know in the US because we have laws to go after them for acting corruptly in other countries. Vaguely asserting corruption without specifics or even naming the perpetrators isn't "taboo", it's just poor form and silly. Letting such vague accusations float without evidence, motive, or even people to blame, leads to nothing good, and only vague distrust, whic…

> Lazy cynicism is itself a form of corruption of one's own mind

I love this way of thinking. I might use this quote down the road

Re: Hardware Attestation as Monopoly Enabler

#307

It is possible to bypass Play Integrity on most devices (even at the "strong" level) using a sewing needle. Specifically, you poke the data lines of the memory bus to induce bitflips, much like I described in https://www.da.vidbuchanan.co.uk/blog/dram-emfi.html This is trickier if your device has the DRAM mounted directly on top of the CPU, but still possible - you'll need to do some BGA rework to get a wire soldered…

Play Integrity will only get more advanced, though

Re: Hardware Attestation as Monopoly Enabler

#309

It is possible to bypass Play Integrity on most devices (even at the "strong" level) using a sewing needle. Specifically, you poke the data lines of the memory bus to induce bitflips, much like I described in https://www.da.vidbuchanan.co.uk/blog/dram-emfi.html This is trickier if your device has the DRAM mounted directly on top of the CPU, but still possible - you'll need to do some BGA rework to get a wire soldered…

Play Integrity will only get more advanced, though

Indeed, my point is less "don't worry about play integrity" and more "don't put it in your app"

Re: Hardware Attestation as Monopoly Enabler

#310
post #259

Earlier quoted context omitted.

RMS found it acceptable to use SunOS initially to create GNU. Open weight models can be a big boost to building Open AI (cough). Progress comes from incremental improvements, -- and open weight models are a big advance in privacy, security, and autonomy over relying on hosted closed systems. Source vs not is only one (important!) dimension, moreover in FSF land they define source as being the preferred form for modif…

>RMS found it acceptable to use SunOS initially to create GNU. Any source on that?

I know it from personal experience using GNU tools on Sun early on (really Solaris in my case, I wasn't quite that early a user), and I think from a talk or essay by RMS but for a moment I worried it might have been personal correspondence. Finding a citation seemed like a fun challenge:

https://www.gnu.org/gnu/thegnuproject.html

> [...] the easiest way to develop components of GNU was to do it on a Unix system, and replace the components of that system one by one. But they raised an ethical issue: whether it was right for us to have a copy of Unix at all.

> Unix was (and is) proprietary software, and the GNU Project's philosophy said that we should not use proprietary software. But, applying the same reasoning that leads to the conclusion that violence in self defense is justified, I concluded that it was legitimate to use a proprietary package when that was crucial for developing a free replacement that would help others stop using the proprietary package.

> But, even if this was a justifiable evil, it was still an evil. Today we no longer have any copies of Unix, because we have replaced them with free operating systems. If we could not replace a machine's operating system with a free one, we replaced the machine instead.

Still leave open the the question of RMS personally using SunOS (as opposed to some other proprietary unix) but I think at this point I'd just go dig up very old GNU sources for evidence of that, but I suspect your question was primarily about RMS' ethical reasoning which is well answered above.

Post reply on HN