Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

631–640 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#631

Earlier quoted context omitted.

> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged

I agree with this. The general population is hopeless, they will hand literally anything away for the least amount of friction. They are also profoundly ignorant. The solution should be to provide the tools necessary to preserve as much agency using technology to people who want to. You should also keep in mind the middle tier technical people who need a bit of hand holding. But do not waste your time on the general…

No, they calculate in the fact of that lack of control into their purchase decision. They mostly didn't want that control in the first place. They just want to _______, for many things you can fill in the blank, including things like look good, appear classy, get high, get laid...

Re: Hardware Attestation as Monopoly Enabler

#632

In 1999, Intel received an absolutely massive amount of opposition when they decided to include a software-readable serial number in their CPUs, so much that they reversed the decision. Then the "security" and Trusted Computing authoritarians continued pushing for TPMs and related tech, and contributed to the rise of mobile walled gardens. Windows 11's TPM requirements were another step towards their goal. The amount…

On the other hand, the TPM spec is pretty complex, especially because they wanted to address privacy issues: the endorsement key, burned by the manufacturer, is only able to encrypt messages and not able to sign them, because this could have been used to track machines. (and this makes a remote attestation protocol much more complex to implement)

So, it looks like they were aware about such kind of issues and tried hard to mitigate them.

Re: Hardware Attestation as Monopoly Enabler

#633
post #316

This is tyranny: making people powerless, afraid of each other, and submissive, per Aristotle's understanding.[1] The technological means are new, to be sure, but the social strategy is as old as civilization. Mark my words. General purpose computing and private, direct communication are things too powerful for a tyrant to permit the people to have. The freedom we've enjoyed for the last several decades, to build wha…

is that tyrant in the room with us now?

Re: Hardware Attestation as Monopoly Enabler

#634

Earlier quoted context omitted.

> It doesn't take much to convince them that Google et al don't have their best interests in mind. They already know it and have experienced it. I think with Apple in particular, this is the issue. Apple have largely demonstrated that they _do_ often have the users best interests in mind (or at least at some point have had) on the basis that the users are Apple’s primary customers. Yes, Apple lock down iOS functional…

Most people just do not think about this as much as we do. We understand that, as the saying goes, if you're not paying for something then you are the product. But less technical people don't consider that, and don't have hoards of technical friends to convince them otherwise. They just think: they using the product, so they're the user, right? We know that's true but it's not the same thing as customer. Most people…

>if you're not paying for something then you are the product.

It seems over the last decade that if you _are_ paying, you are still the product, you're just making more money for the people selling you.

Re: Hardware Attestation as Monopoly Enabler

#635

Earlier quoted context omitted.

What about Apple Wallet? The reality is that there is software dependent on the user being unable to modify it. This safeguards the server against fraudulent users.

Never trust user input. The users already can't modify the server. And what actual applications did you have in mind that warrant throwing everybody under the bus? (by that I mean some applications (allegedly) need it, so it gets forced on everyone)

My banking app already trusts Face ID right now!

Re: Hardware Attestation as Monopoly Enabler

#636
post #600

Earlier quoted context omitted.

If something is actually important, don't put it on a computer. Don't let a computer be in the critical path of anything that actually matters. It's really quite simple. Even before "AI" this technology was not reliable enough for serious, important things--systems that need to be maintainable in adverse conditions (battle damage, etc), systems where failure is not an option (proving your identity, proving your child…

> If you care about your car, truck, tractor, or dozer being maintainable and reliable, don't get one with a computer in it. Got a list of widely available cars and trucks 'without a computer'? :D

Anything older than about 1990, some as new as early 2000s.

Re: Hardware Attestation as Monopoly Enabler

#637
post #316

This is tyranny: making people powerless, afraid of each other, and submissive, per Aristotle's understanding.[1] The technological means are new, to be sure, but the social strategy is as old as civilization. Mark my words. General purpose computing and private, direct communication are things too powerful for a tyrant to permit the people to have. The freedom we've enjoyed for the last several decades, to build wha…

[dead]

Re: Hardware Attestation as Monopoly Enabler

#638

Earlier quoted context omitted.

What about Apple Wallet? The reality is that there is software dependent on the user being unable to modify it. This safeguards the server against fraudulent users.

The one that's so incredibly broken that Apple and Visa keep blaming eachother when they get a report that you can steal any amount by making yourself pass as a transit card ? Cool security theater. https://hackernoon.com/veritasium-stole-$10000-from-mkbhds-l...

This just sounds like a bug. Haven’t delved too deep into it technically though.

Anyway flawed implementation doesn’t mean that hardware attestation is a fundamentally useless primitive. Apple Wallet is responsible for millions of transactions a day.

Re: Hardware Attestation as Monopoly Enabler

#639
post #620

Earlier quoted context omitted.

Look at the last 30 years of computing history? When online banking was first created it was an absolute chaos zone. Everyone was accessing it from desktop machines riddled with viruses and malware. There are endless stories of being discovering their life savings had been wired to Belarus by some malware running on their machine that had grabbed their banking credentials when they logged in. https://www.google.com/s…

>....the calculator devices were retired in favour of smartphones with remote attestation. This was better in literally every way, for 100% of users. Not 100%. A robber can force people to activate facial recognition or finger print sensors. Forcing someone to type a pin code is harder but doable. If one doesn't bring the authenticator & bank card they cant initiate transactions.

Banking apps don't normally force you to use biometrics. They let you use PINs too, at least mine does.

Re: Hardware Attestation as Monopoly Enabler

#640
post #560

It's the 3rd or 4th of threads like this in the front page and it's still not clear to me what are the alternatives that privacy advocates vouch for? Dead internet theory is happening, you have botnets with more budget than most of the third world countries and you could also add openclaw usage to same bucket. There's a real need for a protocol or specification for how to attest that an action was really done by a hu…

[dead]
Post reply on HN