Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

361–370 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#362

Earlier quoted context omitted.

It’s not a proper noun, and this is HN: pedantry is par. “The president of Xyz” capitalizes the X in Xyz(pn) but not the P in president(n). However, the P in President(pn) is capitalized when it’s a Title suffixed to a Name - but that varies per country by what they title their president-equivalent locally and isn’t always translated, while the concept-slash-role label of ‘president’ in English generally does not (an…

President is a title here so Capitalization is correct use. That last one wasn’t. To be pedantic, we all know which one I was referring to.

They’re trolling.

Re: Hardware Attestation as Monopoly Enabler

#364

In 1999, Intel received an absolutely massive amount of opposition when they decided to include a software-readable serial number in their CPUs, so much that they reversed the decision. Then the "security" and Trusted Computing authoritarians continued pushing for TPMs and related tech, and contributed to the rise of mobile walled gardens. Windows 11's TPM requirements were another step towards their goal. The amount…

Weird rant. TPMs are great. The modern computing landscape needs a safe place to put secrets. It's what made the iPhone (Secure Enclave is effectively a TPM) years ahead of Android in terms of security.

The problem isn't the TPM, but attestation. As soon as the TPM is required to not be under your control to get access to Y, bad things happen.

Hell, in actuality, the problem isn't even attestation, its policy. The EU Parliament (the one the people vote for, the Commission are cronies) might eventually force corporations into something more citizen-friendly. Neither Apple, Google or Microsoft is going to drop a market that big.

Re: Hardware Attestation as Monopoly Enabler

#365

Earlier quoted context omitted.

You have given a situation where there are a 3 players - a very concentrated market. Give an example with 30 players and think through all the implications for all the actors. You'll quickly realize it's a total disaster. Building broad trust requires scale on some dimension.

How is it in any way a disaster? Consider how Linux distributions work. Every distribution is distributing variants on the same kernel and utilities, but there are hundreds of distributions and dozens of popular ones each with their own repositories. You can choose whichever you like, and make a different choice than someone else. Coming in at #31 on DistroWatch is a lightweight distribution called Alpine Linux. It's…

The long tail of linux distributions work precisely because they need very little trust and are consumed by highly technical users who can verify all manner of things themselves. They especially don't require multi-party verification.

Broad trust is required in lots of situations. Hardware attestation, financial clearing networks, or even physical supply chains. Ie, you have multiple independent parties who need mutual, verifiable trust to operate. Establishing that requires transaction costs like audits, SLAs, legal liability, and cryptographic integration. The economics don't work for 30 different players to cross-verify each other. So, we have oligopolies...

Re: Hardware Attestation as Monopoly Enabler

#366

Earlier quoted context omitted.

Closed or open source doesn't matter; it's the ability to control them that's important. People have been cracking and patching for decades without source, but they have that control. Contrast this with remote attestation, where they might show you the source code for everything but you're still powerless to do anything.

> Closed or open source doesn't matter; it's the ability to control them that's important. People have been cracking and patching for decades without source, but they have that control. You have no idea what has been baked into the weights in the training process. In theory you could find biases and attempt to "patch" them out, but its a vastly different process vs. patching machine code. Consider what would happen i…

People are already patching these models using abliteration to prevent them from refusing any request, so it is possible for end users to change them in meaningful ways. You can download abliterated models right now from Hugging Face that will respond to all kinds of requests that frontier models refuse.

Re: Hardware Attestation as Monopoly Enabler

#367

Earlier quoted context omitted.

They’re trolling.

I'm not.

If you’re not, and I say this in good faith, take your own advice around your tone. Making assumptions about other people, and then doubling down when they correct you, comes across as a kind of horrible I doubt you truly are.

Re: Hardware Attestation as Monopoly Enabler

#368

Earlier quoted context omitted.

I'm not.

If you’re not, and I say this in good faith, take your own advice around your tone. Making assumptions about other people, and then doubling down when they correct you, comes across as a kind of horrible I doubt you truly are.

I say this in good faith: oh, stop.

Re: Hardware Attestation as Monopoly Enabler

#369

Earlier quoted context omitted.

Would like to read a writeup on this, I was certain it was going to be something like this from the app's announcement. Also I recall a discussion on Graphene's forums that DRM ID is not only retained there, but stays the same across profiles.

I simplified the process in my description. The DRM ID Android has is not what I was referring to. I was referring to the static private key that is stored in the silicon. At any time an application can initiate a license request process using DRM APIs which will elicit an unchangeable HWID from your device. The only protection is that it will be encrypted for an authorized license server private key so collusion may…

Citation?

Re: Hardware Attestation as Monopoly Enabler

#370

Earlier quoted context omitted.

I was just talking about this today: I have an internal convention to not capitalise LLMs when talking about them as if they were people; so claude is not capitalised, and the internal LLM-based service agent we're building, rex, is not capitalised. I realise this breaks the capitalisation of proper nouns; claude is a name and therefore a proper noun and therefore should be capitalised. But I like that there's a sign…

> the thing I'm talking about is not a person Countries, companies, religions; hell, planets and galaxies–none of these are sapient. Yet we capitalise them. I'll go out into the deep end for a second with a hypothesis: I think we capitalise because it makes printed text easier to scan. The words you need to spend more time on are capitalised because they aren't ones you can just roll through. This is also why the nut…

I completely agree with your hypothesis. And the ridiculous effect that Trump's random capitalisation has, both of making his text (even) harder to read, and of giving the impression that he doesn't actually know how to write English.

My additional hypothesis is that capitalisation accords respect, something along the lines of "this is a thing apart, something with a name, so we capitalise it". Not capitalising an actual human's name would seem disrespectful to me.

Post reply on HN