Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

551–560 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#551
post #6

Our civilization desperately needs a method to modify modern microelectronics after manufacturing that can be used at least in a well-equipped repair shop, and it needs it yesterday. Alternatively, just make it illegal to ship any kind of initial bootloader as part of a CPU's/SoC's mask ROM in any computing device that is marketed as a general-purpose one. I.e. the first instruction that the CPU executes after reset…

Or maybe we should just get rid of the "breaking DRM is illegal"-laws. See https://pluralistic.net/2026/01/01/39c3/

Those laws should die, but that's besides the point.

Modern cryptography allows for making DRM incredibly hard to break. And the disadvantage of "hardware attestation" DRM is that you have to break it not once, on a single device, the way you do to dump a "protected" movie, but on every single device that you want to use.

Re: Hardware Attestation as Monopoly Enabler

#552
post #543

Earlier quoted context omitted.

> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged

Yes, but most people don't realize it, simply because they have been conditioned from the beginning that the only way to run anything on an iOS device is via the app store. With Apple customers, a better argument to make is to say that Apple applies a 30% 'tax' on all activity on their phones. That they are being forced to pay more compared to non Apple users in spite of having bought their device fair and square.

I have been using Apple devices for almost 20 years, and I have never been forced to pay a 30% tax on all activity on my phone. I can avoid it by buying directly from the seller's website, and also I just avoid buying software subscriptions in general, but especially from the App Store.

99% of the payment activity I do on my phone (buying retail goods, travel arrangements, paying invoices) has no additional cost.

Re: Hardware Attestation as Monopoly Enabler

#553

Earlier quoted context omitted.

> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged

Because Apple always did this, everybody knew this and people buy Apple exactly because of this. Google now pulls the rug on Android which is a whole different story because it used to be open. The whole idea of Android was to be open.

> Because Apple always did this, everybody knew this and people buy Apple exactly because of this.

Is that really so? Does the average iPhone user actually factor the app store tax into their decision to purchase the device? Or do they just assume that is just how all software works because they have no exposure to software ecosystems outside the iPhone app store

Re: Hardware Attestation as Monopoly Enabler

#554
post #543

Earlier quoted context omitted.

Yes, but most people don't realize it, simply because they have been conditioned from the beginning that the only way to run anything on an iOS device is via the app store. With Apple customers, a better argument to make is to say that Apple applies a 30% 'tax' on all activity on their phones. That they are being forced to pay more compared to non Apple users in spite of having bought their device fair and square.

I have been using Apple devices for almost 20 years, and I have never been forced to pay a 30% tax on all activity on my phone. I can avoid it by buying directly from the seller's website, and also I just avoid buying software subscriptions in general, but especially from the App Store. 99% of the payment activity I do on my phone (buying retail goods, travel arrangements, paying invoices) has no additional cost.

No? Apple charges a fee on every app sale. Where do you think the app makers pay that walled garden tax?

Re: Hardware Attestation as Monopoly Enabler

#555
post #473

Earlier quoted context omitted.

> Passkeys are better passwords. They need a TPM. Passkeys absolutely do not need TPM. You can get passkey support in any browser with a simple 1password plugin without any TPM hardware. The same way you could get a TOTP app on your phone without any TPM. TPMs are just an extra security layer for most usages. They are mainly a necessity for some shady business like DRMs.

> Passkeys absolutely do not need TPM. They do not, but how does the service you’re using know your passkey is secure? For all they know you’re just some gullible user that clicks through every fishing email you get. You’re dumb, weak, helpless, they gotta protect you from this scary world out there, and maybe yourself as well. They can’t do that if they allow your passkey to be stored anywhere you control. KeepassXC…

> For all they know you’re just some gullible user that clicks through every fishing email you get.

Passkeys are non-phishable. That's part of their schtick. I'm not a huge passkey fan myself, but this is a real benefit.

Re: Hardware Attestation as Monopoly Enabler

#556
post #553

Earlier quoted context omitted.

Because Apple always did this, everybody knew this and people buy Apple exactly because of this. Google now pulls the rug on Android which is a whole different story because it used to be open. The whole idea of Android was to be open.

> Because Apple always did this, everybody knew this and people buy Apple exactly because of this. Is that really so? Does the average iPhone user actually factor the app store tax into their decision to purchase the device? Or do they just assume that is just how all software works because they have no exposure to software ecosystems outside the iPhone app store

They factor in a more "clean" appstore yes. Not the tax itself but they usually appreciate apple having more polished apps in general (given that the Google Playstore is full of trash).

Re: Hardware Attestation as Monopoly Enabler

#557

Earlier quoted context omitted.

Hardware attestation is like hardware DRM. It is intended to limit and restrict abundance. Abundance of clients (as a proxy for user attention) and abundance of copying, access and replay (as a proxy for "piracy"), resp. It won't matter to the masses, it won't hamper "bad actors" because hackers will find flaws instantly. It's just enshitfication.

I hope you're right. I truly do. > hackers will find flaws instantly Yeah. https://tee.fail/ The ability to circumvent these cryptographic attestations and pretend to be a "pristine" corporate owned device while in fact being free will be a key strategic capability in the future. They will no doubt pour billions into improving the technology though. I'm not sure if such a capability can be maintained over the long te…

It probably won't matter to the average user: buy Apple, buy Google and be (little bit less) happy while your access to the free web gets little more enshittified...

...But there is always at least one hacker.

The issue with hardening DRM is that at the core it's hard to protect against an adversary that with physical access to the device that keeps the very secret. From the vendor perspective, the very customer paying you is your potential enemy.

That means that the root of trust isn't itself protected with cryptography. Instead, it relies on security-through-obscurity, Faraday cages, fuses, anti-tampering and lots of glue. And it's a numbers game if there are thousands of different devices, potentially with different flaws while your adversaries are hidden among billions of customers.

There is still a gap between the hacker and main-stream availability, though: laws and legalism, like DMCA that penalize disclosing how the obfuscation and all work.

Re: Hardware Attestation as Monopoly Enabler

#558
post #554

Earlier quoted context omitted.

I have been using Apple devices for almost 20 years, and I have never been forced to pay a 30% tax on all activity on my phone. I can avoid it by buying directly from the seller's website, and also I just avoid buying software subscriptions in general, but especially from the App Store. 99% of the payment activity I do on my phone (buying retail goods, travel arrangements, paying invoices) has no additional cost.

No? Apple charges a fee on every app sale. Where do you think the app makers pay that walled garden tax?

Buying apps is hardly "all activity on a phone". It's completely inconsequential to my spend since summer of 2008, when I began using Apple products. Maybe a couple hundred dollars in total app store purchases? It would make no sense for me to base a decision about devices I use day and night over that small amount of money (30% of a couple hundred dollars).

Re: Hardware Attestation as Monopoly Enabler

#559
post #543

Earlier quoted context omitted.

Yes, but most people don't realize it, simply because they have been conditioned from the beginning that the only way to run anything on an iOS device is via the app store. With Apple customers, a better argument to make is to say that Apple applies a 30% 'tax' on all activity on their phones. That they are being forced to pay more compared to non Apple users in spite of having bought their device fair and square.

I have been using Apple devices for almost 20 years, and I have never been forced to pay a 30% tax on all activity on my phone. I can avoid it by buying directly from the seller's website, and also I just avoid buying software subscriptions in general, but especially from the App Store. 99% of the payment activity I do on my phone (buying retail goods, travel arrangements, paying invoices) has no additional cost.

You're correct. You've just paid it on every app store purchase, and every in app purchase. That's because Apple, despite trying, have failed to completely lock in the payment infrastructure.

They really want to though. Maybe consider that.

Re: Hardware Attestation as Monopoly Enabler

#560
It's the 3rd or 4th of threads like this in the front page and it's still not clear to me what are the alternatives that privacy advocates vouch for? Dead internet theory is happening, you have botnets with more budget than most of the third world countries and you could also add openclaw usage to same bucket. There's a real need for a protocol or specification for how to attest that an action was really done by a human and that human can be proven to be the one the service provider think they are. I don't think cryptography by itself would solve that right now.
Post reply on HN