Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

351–360 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#351

Earlier quoted context omitted.

> The President, within this context, identifies a single entity. As such, it is a proper noun Yeah, no. You're just making things up to suit your position like the president does.

> no. You're just making things ...this isn't a counterargument. I can similarly assert you're justing making stuff up, which isn't untrue, either way, since we're talking about language, a wholly made-up enterprise. What's your contention that the President, within the context of the American presidency, does not refer to a single entity? Is this a preference? Or something you actually believe is incorrect?

You got the impression I was trying to argue with you? Go look it up like the president doesn't. I'm personally not a recognized grammar authority.

Re: Hardware Attestation as Monopoly Enabler

#352

Earlier quoted context omitted.

> Why was this decision ever made? because it wasn't made the decision which was made was having a digital ID wallet, that this needs hardware attestation (or something comparable) is somewhat of a direct consequence of existing laws/regulations regarding making IDs forgery safe it also is a phone only application the huge huge majority of phones runs Googled Android/iOS, so you support them if there where a relevant…

Have you seen our President? Minor conveniences are what trigger him into launching full blown DOJ investigations, wars, and economic disaster. If he realizes he can just "turn off" the EU, oh, he will threaten that on Truth Social tonight in a rant about how they should make a deal or else.

I'd like to see if he can be convinced into going after Google and effectively stopping remote attestation. One can certainly dream...

Re: Hardware Attestation as Monopoly Enabler

#353

Earlier quoted context omitted.

I was just talking about this today: I have an internal convention to not capitalise LLMs when talking about them as if they were people; so claude is not capitalised, and the internal LLM-based service agent we're building, rex, is not capitalised. I realise this breaks the capitalisation of proper nouns; claude is a name and therefore a proper noun and therefore should be capitalised. But I like that there's a sign…

> the thing I'm talking about is not a person Countries, companies, religions; hell, planets and galaxies–none of these are sapient. Yet we capitalise them. I'll go out into the deep end for a second with a hypothesis: I think we capitalise because it makes printed text easier to scan. The words you need to spend more time on are capitalised because they aren't ones you can just roll through. This is also why the nut…

You clearly speak only one language.

Re: Hardware Attestation as Monopoly Enabler

#354

It is possible to bypass Play Integrity on most devices (even at the "strong" level) using a sewing needle. Specifically, you poke the data lines of the memory bus to induce bitflips, much like I described in https://www.da.vidbuchanan.co.uk/blog/dram-emfi.html This is trickier if your device has the DRAM mounted directly on top of the CPU, but still possible - you'll need to do some BGA rework to get a wire soldered…

Much like DRM, the point is that we shouldn't have to fight this BS in the first place.

Re: Hardware Attestation as Monopoly Enabler

#355

The linked article only seems to cover Google and Android devices. Microsoft also have their take on this. > "Microsoft Pluton security processor is a chip-to-cloud security technology built with Zero Trust principles at the core. Microsoft Pluton provides hardware-based root of trust, secure identity, secure attestation, and cryptographic services." https://learn.microsoft.com/en-us/windows/security/hardware-...

Related article about that 4 years ago: https://news.ycombinator.com/item?id=29859106

It's amazing to see how many "but it won't happen" comments there.

Re: Hardware Attestation as Monopoly Enabler

#356
post #212

With all of the discourse around hardware attestation, digital ID, and age verification in recent weeks/months, is there actually any good solution to the problems these existing tools (Privacy Pass, WEI, Fraud Defense, uploading IDs) claim to solve? Are there open and privacy-preserving standards that can solve the problem of bots and minors? If not, what would be required to establish one, and is it realistic? Busi…

What even is the problem? I keep my kids computers in the living room where it's easy to see what they are doing. Their lan shuts down at night when I'm asleep. They don't get full control of their own cell phone until they are around 16-years old. Bots on social media discourage me from using it which is a Good Thing if you ask me.

> Bots on social media

... are not problems, no - but bots in general are

Re: Hardware Attestation as Monopoly Enabler

#357
post #223

Earlier quoted context omitted.

The local models are still centralized and proprietary. They are basically closed source software.

Closed or open source doesn't matter; it's the ability to control them that's important. People have been cracking and patching for decades without source, but they have that control. Contrast this with remote attestation, where they might show you the source code for everything but you're still powerless to do anything.

> Closed or open source doesn't matter; it's the ability to control them that's important. People have been cracking and patching for decades without source, but they have that control.

You have no idea what has been baked into the weights in the training process. In theory you could find biases and attempt to "patch" them out, but its a vastly different process vs. patching machine code.

Consider what would happen if Google's open weight models were best at writing code targeting Google's services vs. their competitors? Is this something that could be patched? What if there were more subtle differences that you only notice much later after some statistical analysis?

Re: Hardware Attestation as Monopoly Enabler

#358

Earlier quoted context omitted.

They can also shut down all European payment cards.

Maybe not all of them, but certainly a few large, popular ones. You bring up a good point though, it seems surprising that Wero/PEPSI don't have more momentum. Maybe Europeans hate their continental neighbors more than American financial conglomerates.

We just don't know much about one another.

I never really thought about it until I saw this comment:

https://news.ycombinator.com/item?id=45993140

Re: Hardware Attestation as Monopoly Enabler

#359

Earlier quoted context omitted.

> the thing I'm talking about is not a person Countries, companies, religions; hell, planets and galaxies–none of these are sapient. Yet we capitalise them. I'll go out into the deep end for a second with a hypothesis: I think we capitalise because it makes printed text easier to scan. The words you need to spend more time on are capitalised because they aren't ones you can just roll through. This is also why the nut…

You clearly speak only one language.

Wrong again!

Re: Hardware Attestation as Monopoly Enabler

#360

Seems to me like Microsoft might be opposed to this duopoly and have pockets deep enough to fight it, right? For one, this would make their possible re-entry into the mobile space harder and more costly but I guess it'll inevitably become a standard that other providers could fulfill.

On the contrary, Microsoft was one of the early promoters of such technology; look up Palladium/TCG/NGSCB.
Post reply on HN