Earlier quoted context omitted.
Yeah, but they aren't. Google certifies devices unpatched for the last 10 years, rooted, riddled with the malware, because the keys have leaked. Google knows and still sells the lie. But you should know better. Google is not selling the actual security, it's just protecting its business.
Google's business is advertising. Right now they don't care whether your phone is "authentic" or secure, because it doesn't cost them money. As AI-enabled bot fraud rises, they will care. Fighting this requires identifying human beings, and that requires trusted devices to be associated with human beings. We're in the foothills still, but look forward and up at where adtech is going.
Hardware Attestation as Monopoly Enabler
371–380 of 799 posts
Re: Hardware Attestation as Monopoly Enabler
#372Earlier quoted context omitted.
> In 1999, Intel received an absolutely massive amount of opposition when they decided to include a software-readable serial number in their CPUs, so much that they reversed the decision. > It turns out a significant (but hopefully decreasing) number of the population is easily coerced into anything when "security" is given as a justification. The people who opposed Intel are now telling each other how hopeless and p…
The people who opposed Intel are now telling each other how hopeless and powerless they are. I don't think those are the same people. I, for one, will continue this fight by telling everyone I know about the fact that Google is going for absolute control of the Internet, and by extension, everyone's lives. They have already become an unelected global government.
Re: Hardware Attestation as Monopoly Enabler
#373Earlier quoted context omitted.
So a vote happened, and when it didn’t go their way, huge company threatened a huge lawsuit that the township and citizens couldn’t afford, to get their way anyway. Standard corporate bullying tactic in America. The story perfectly exemplifies how little democratic control the public has over what corporations do in and do to their community.
The reason the would-be purchaser sued the state is that they had a plausible argument that the township's denial was illegal under Michigan state law. There are quotes in the article from the Governor's office that they support the construction of data centers. This isn't democracy not working; it's that the efforts need to go up to the state level in the hierarchy.
Re: Hardware Attestation as Monopoly Enabler
#374I am reminded of the period when secure boot was being developed for PCs. Microsoft certainly wanted to be the only company whose OS was allowed to boot with secure boot turned on. Google should not be allowed to close the supposedly "open" ecosystem they created any more than Microsoft was allowed to.
That said, there are countless mobile devices with locked bootloaders and and boot integrity attestation that will never run anything other than OEM OSes. That's equivalent to a locked Secure Boot + UKI-like system on PCs and it's already here.
Re: Hardware Attestation as Monopoly Enabler
#375In 1999, Intel received an absolutely massive amount of opposition when they decided to include a software-readable serial number in their CPUs, so much that they reversed the decision. Then the "security" and Trusted Computing authoritarians continued pushing for TPMs and related tech, and contributed to the rise of mobile walled gardens. Windows 11's TPM requirements were another step towards their goal. The amount…
Weird rant. TPMs are great. The modern computing landscape needs a safe place to put secrets. It's what made the iPhone (Secure Enclave is effectively a TPM) years ahead of Android in terms of security. The problem isn't the TPM, but attestation. As soon as the TPM is required to not be under your control to get access to Y, bad things happen. Hell, in actuality, the problem isn't even attestation, its policy. The EU…
Re: Hardware Attestation as Monopoly Enabler
#376Earlier quoted context omitted.
> Closed or open source doesn't matter; it's the ability to control them that's important. People have been cracking and patching for decades without source, but they have that control. You have no idea what has been baked into the weights in the training process. In theory you could find biases and attempt to "patch" them out, but its a vastly different process vs. patching machine code. Consider what would happen i…
People are already patching these models using abliteration to prevent them from refusing any request, so it is possible for end users to change them in meaningful ways. You can download abliterated models right now from Hugging Face that will respond to all kinds of requests that frontier models refuse.
Re: Hardware Attestation as Monopoly Enabler
#377In 1999, Intel received an absolutely massive amount of opposition when they decided to include a software-readable serial number in their CPUs, so much that they reversed the decision. Then the "security" and Trusted Computing authoritarians continued pushing for TPMs and related tech, and contributed to the rise of mobile walled gardens. Windows 11's TPM requirements were another step towards their goal. The amount…
Weird rant. TPMs are great. The modern computing landscape needs a safe place to put secrets. It's what made the iPhone (Secure Enclave is effectively a TPM) years ahead of Android in terms of security. The problem isn't the TPM, but attestation. As soon as the TPM is required to not be under your control to get access to Y, bad things happen. Hell, in actuality, the problem isn't even attestation, its policy. The EU…
Re: Hardware Attestation as Monopoly Enabler
#378I am reminded of the period when secure boot was being developed for PCs. Microsoft certainly wanted to be the only company whose OS was allowed to boot with secure boot turned on. Google should not be allowed to close the supposedly "open" ecosystem they created any more than Microsoft was allowed to.
> the period when secure boot was being developed for PCs. You mean right now? At a firmware level, the scope of "trusted computing" is expanding with every passing year. > close the ecosystem they created any more than Microsoft was allowed to. We are in the process of allowing Microsoft to close the PC platform. TPM is required to run Windows now. Nearly every new PC ships with "secure boot" enabled, adding a new t…
All modern PCs ship with Pluton coprocessors. The end-to-end remote attestation hardware infrastructure is all already there, waiting for someone to flip a switch and turn it on.
Re: Hardware Attestation as Monopoly Enabler
#379In 1999, Intel received an absolutely massive amount of opposition when they decided to include a software-readable serial number in their CPUs, so much that they reversed the decision. Then the "security" and Trusted Computing authoritarians continued pushing for TPMs and related tech, and contributed to the rise of mobile walled gardens. Windows 11's TPM requirements were another step towards their goal. The amount…
Weird rant. TPMs are great. The modern computing landscape needs a safe place to put secrets. It's what made the iPhone (Secure Enclave is effectively a TPM) years ahead of Android in terms of security. The problem isn't the TPM, but attestation. As soon as the TPM is required to not be under your control to get access to Y, bad things happen. Hell, in actuality, the problem isn't even attestation, its policy. The EU…
I -- literally -- do not care about a single "account" in any "service" I use aside from my email and bank account. Most people would add a few social media accounts to that list.
You don't need a "place to put secrets". Your iPhone app does not do anything important enough to require a "trusted chain" of cryptographic bullshit, just use a password and Google/Apple login.
Re: Hardware Attestation as Monopoly Enabler
#380Earlier quoted context omitted.
I like to ride my bicycle with my friends in rides organized by the (Pacific Northwest) Cascade Bicycle Club. They require that I solve a Google reCAPTCHA in order to register for a ride. Google is already completely locking me out from being able to do that. When I try to click on the squares to select whatever items it's asking, it indefinitely loops. When I try using the audio version, it completely blocks me from…
I also had a similar issue with Cascade Bicycle Club - they chose to organize things via WhatsApp, and since I am (inexplicably) banned from opening a Meta account I was completely left out of the group and missed out on many rides/details that were only shared via WhatsApp. When I tell people that this is even possible I get wide-eyed stares — as if they never contemplated that Meta could exercise their right to ban…