Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

501–510 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#501
post #447

I always say this when this topic comes up: remote attestation will be how our computing freedom dies. They've made it so that it doesn't even matter if they allow you to install whatever you want. Anything that isn't corporate owned is banned. Own your device? You "tampered" with it. You're banned. From everything. You're ostracized from digital society. You're not even a citizen, much less a second class citizen. E…

For once, we may be "saved" thanks to Trump. Because of the brutal change in geopolitics he triggered, the EU is now actively looking at all the hard dependencies on US controlled systems. Android and iOS are two of them. I cannot tell if the alternative solution will be better, but I do think we will develop alternatives.

The EU is only making these statements until the US has a new president (with the same ideas of Trump, as has always been the case, but saying nice things in public).

Also, in the mean time, their announced "sovereign solutions for the European citizen" look ridiculous: now you'll be free from Visa and Mastercard for your payments but at the same time you'll need a phone approved by either Apple or Google.

Re: Hardware Attestation as Monopoly Enabler

#502

I always say this when this topic comes up: remote attestation will be how our computing freedom dies. They've made it so that it doesn't even matter if they allow you to install whatever you want. Anything that isn't corporate owned is banned. Own your device? You "tampered" with it. You're banned. From everything. You're ostracized from digital society. You're not even a citizen, much less a second class citizen. E…

> Own your device? You "tampered" with it. You're banned. From everything.

Don't worry officer, my device is completely clean. Here you go check it. Why yes, I absolutely only ever use it for banking and updating linkedin on a suspiciously empty gmail, and keep it on silent 100% of the time. What's so odd about that? What? No, I just re-read a lot of books, that's my hobby, I read Catcher In The Rye 20 times a month.

...

It's about time people realize the concept of a real phone and a civilian phone as one and the same is dead.

In fact.

You don't need a "real" phone. Just the civilian one.

I use what's basically a portable retroconsole for entertainment. Including reading, incidentally. From its perspective, it is just a computer. Let's make it a competition, puny phones versus portable computing. Name me one thing you think it can't do, in return, I'll fire two YOUR phone can't right now, back at you. I'll forward two: It can run tmux and has a copyparty toggle for a portable filestorage on it. Yes, you can do both on the phone. But yours can't right now, and I you will suffer trying tog get it, while mine, it was 2 command lines and one config file each.

Re: Hardware Attestation as Monopoly Enabler

#504

I always say this when this topic comes up: remote attestation will be how our computing freedom dies. They've made it so that it doesn't even matter if they allow you to install whatever you want. Anything that isn't corporate owned is banned. Own your device? You "tampered" with it. You're banned. From everything. You're ostracized from digital society. You're not even a citizen, much less a second class citizen. E…

I think it's quite telling that this comment was written in Brazil. The so-called Third World is the future source of freedom (or Western countries that become third world perhaps). It may not be a bad idea now to start building open compute and banking alternative ecosystems based in those countries, marketed at Western citizens.

Re: Hardware Attestation as Monopoly Enabler

#505

Earlier quoted context omitted.

> Do you consider being banned in a video game because of hacking to be an example of something killing computing freedom? No. It's the constant attempts to invade our computers and "prevent" the unwanted behavior that are problematic. See kernel level anticheat nonsense. They want to own our computers. > if they want to play with others who don't want to play with cheaters then they have to use the official client T…

>See kernel level anticheat nonsense. This nonsense mainly exists only because the operating system is unable to attest that it the app is secure and the right app is what is running. >It's their computer, it should run whatever software they want. I agree, but companies shouldn't be forced to match cheaters with legitimate players. Cheaters just can't secretly be cheating.

The problem is not that the OS can’t attest the app is secure. The problem with cheating is that the game servers cannot attest the client is genuine in all aspects that matter: non-modified client, running in an environment where there is no inspection of its memory for map hacks, aim bots, and more. The only way to do that is a remote attestation of the entire chain: hardware, locked down OS, app. (If the OS isn’t locked down it can’t prevent the player from running cheating software.)

The choice is simple: tolerate some level of online cheating, or require remote attestation to run the game. If you ask me, I’d rather take the first option. Locked down game console already make me a bit queasy. A locked down desktop, laptop, or palmtop? That’s not acceptable. People should be able to run any program they want on their computers. If that means the end of online gaming, so be it.

Re: Hardware Attestation as Monopoly Enabler

#506

Earlier quoted context omitted.

Can you show me examples where locking down an OS has prevented fraud in banking? Honestly, if the only way to secure your banking system is by locking down users' devices, there is something really bad going on at your end, security-wise. Your system should be secure even without locking down user hardware.

Look at the last 30 years of computing history? When online banking was first created it was an absolute chaos zone. Everyone was accessing it from desktop machines riddled with viruses and malware. There are endless stories of being discovering their life savings had been wired to Belarus by some malware running on their machine that had grabbed their banking credentials when they logged in. https://www.google.com/s…

> Secondly, it's a lot more convenient to use a device that's always with you than a dedicated standalone single-use computer.

The price the owner pays for this is that they're locked out of their own expensive general-purpose computing device while still having to bear all the inconveniences (babysit OS updates, configure stuff, keep it charged, have the battery fail, buy a new device every five years, etc.)

In the meantime, the standalone chip-and-TAN device costs 30 bucks, is powered by three AAA batteries that hold their charge for five years, lives for 20 years, and never needs a single software update.

I'd choose the small single-purpose device over the enshittified, locked-down smartphone every single time.

Re: Hardware Attestation as Monopoly Enabler

#507
post #427

Earlier quoted context omitted.

I have 2 servers, Alice and Bob, Bob has a secret, I want Bob to be able to share that secret with Alice. However, I want Alice to be able to prove to Bob that it is actually Alice, that it is running the correct AliceOS, and that AliceOS was loaded on bare metal Alice without nefarious pre-book or virtualization hooks. A TPM with measured boot (SecureBoot) does exactly this, remote attestation is how Alice proves to…

As someone who wanted to improve users security, that’s exactly why I find this thread fanatical opposition to attestation baffling. Nearly everyone uses a device that supports hardware attestation. It’s the best available tool to protect users from malware. We do implement a fallback that lowers security but lets the few users who have devices not able to attest properly to continue, but that really lowers security…

If the price to pay for security is freedom, then let users's devices be insecure. With time, they will learn good security hygiene. And if they don't, maybe they don't deserve it.

Re: Hardware Attestation as Monopoly Enabler

#508
post #447

Earlier quoted context omitted.

For once, we may be "saved" thanks to Trump. Because of the brutal change in geopolitics he triggered, the EU is now actively looking at all the hard dependencies on US controlled systems. Android and iOS are two of them. I cannot tell if the alternative solution will be better, but I do think we will develop alternatives.

The EU is only making these statements until the US has a new president (with the same ideas of Trump, as has always been the case, but saying nice things in public). Also, in the mean time, their announced "sovereign solutions for the European citizen" look ridiculous: now you'll be free from Visa and Mastercard for your payments but at the same time you'll need a phone approved by either Apple or Google.

And there is also "sovereign cloud" by microsoft!

Re: Hardware Attestation as Monopoly Enabler

#509

Earlier quoted context omitted.

We had fun in online games without kernel level nonsense. Why do I need to compromise my hardware when the problem is an outlier in the social graph? Anticheat is part an arms race and part just raising the bar so people cant cheat too easily. That said you can feed a video feed into a Kria K26 or even a pi or jetson and make automatic targeting completely transparant to the kernel. Then what? Hardware attestation in…

>We had fun in online games without kernel level nonsense. You might of. But there was a percentage of players turned away by cheaters or even just had a bad experience one day because of one. At scale this can cause a bad experience for a ton of players so trying to stop as many cheaters as possible does matter. >Why do I need to compromise my hardware You don't have to compromise anything. In fact it is optimal to…

> You don't have to compromise anything.

So… I don’t have to compromise the ability to run any program I want on my machine, and I don’t have to compromise the ability to be root on my machine. Right? And of course, when I say "me", I’m talking about everyone, including cheaters. Meaning, we don’t have to compromise the cheater’s ability to run any program they want (that would include cheats), nor their ability to be root on their machine.

> In fact it is optimal to have the system be as secure as possible that way cheats can't mess with the game.

Secure for the game company you mean. I want a computer that’s secure for me, that responds to my commands. And again, "me" includes everyone and cheaters too.

---

The online gaming industry is not worth sacrificing individual ownership of computers.

Re: Hardware Attestation as Monopoly Enabler

#510

Earlier quoted context omitted.

I don't actually believe this. People don't actually believe every car should have a GPS tracker so that if a pedophile drives a car, the police can track it. That is a ridiculous argument, and if they make it, there should be something you can say to make it blow up in their face. Unfortunately, as we've all now discovered, winning arguments isn't about being right, so I don't know which words you can say to make th…

> People don't actually believe every car should have a GPS tracker so that if a pedophile drives a car, the police can track it. It's not about what people believe, but what they are willing to publicly push back against. If such a law was proposed today, I bet it would pass because the only discussions around it would be whether the data can be kept safe and what punishments to dole out if the car owner access this…

This was already in place in the EU back in 2024. Lookup DDAW. You can turn off warnings, but it will still keep on monitoring the driver
Post reply on HN