Earlier quoted context omitted.
> Secondly, it's a lot more convenient to use a device that's always with you than a dedicated standalone single-use computer. The price the owner pays for this is that they're locked out of their own expensive general-purpose computing device while still having to bear all the inconveniences (babysit OS updates, configure stuff, keep it charged, have the battery fail, buy a new device every five years, etc.) In the…
This reminds me of crypto wallets. I also dispute mike_hearn 's: > Smartphone HW attestation is better in every way They're still prone to side-channel attacks like SPECTRE. Crypto wallets are practically immune because they're air-gapped. [edit] I just realised that's Mike Hearn of early BTC fame. I suppose he would know what a crypto wallet is.
Hardware Attestation as Monopoly Enabler
641–650 of 799 posts
Re: Hardware Attestation as Monopoly Enabler
#642Earlier quoted context omitted.
> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged
I agree with this. The general population is hopeless, they will hand literally anything away for the least amount of friction. They are also profoundly ignorant. The solution should be to provide the tools necessary to preserve as much agency using technology to people who want to. You should also keep in mind the middle tier technical people who need a bit of hand holding. But do not waste your time on the general…
Re: Hardware Attestation as Monopoly Enabler
#643The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…
If you don't address this tradeoff you're not really engaging the issue.
What I think we need is a professional, well-informed advocate of freedom who is willing to seriously discuss the tradeoff and concede that neither extreme is ideal.
Re: Hardware Attestation as Monopoly Enabler
#644Re: Hardware Attestation as Monopoly Enabler
#645Earlier quoted context omitted.
And one of the threat models that police use in the US is tracking women suspected of going for abortions through the use of road cameras, and other surveillance methods. Once you have the attestation in place you have no guarantee who is going to get access to data like what apps are present on your device, and there will be nothing you can do to stop it. Meanwhile, we could educate people against common scams. How…
You can't educate (many) people against common scams. But people should have the freedom to opt out of surveillance in their private lives, at the risk of exposure to scams.
Re: Hardware Attestation as Monopoly Enabler
#646Earlier quoted context omitted.
I agree with this. The general population is hopeless, they will hand literally anything away for the least amount of friction. They are also profoundly ignorant. The solution should be to provide the tools necessary to preserve as much agency using technology to people who want to. You should also keep in mind the middle tier technical people who need a bit of hand holding. But do not waste your time on the general…
No, they calculate in the fact of that lack of control into their purchase decision. They mostly didn't want that control in the first place. They just want to _______, for many things you can fill in the blank, including things like look good, appear classy, get high, get laid...
The average person is not calculating anything but price, is it what everyone else is using, is it new etc. Very low level calculations. They aren't asking "can I install applications from outside the app store?". Etc.
Re: Hardware Attestation as Monopoly Enabler
#647The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…
There is a tradeoff between the freedom users have on their devices on one side, and the likelihood less sophisticated users will get their information stolen or their devices pwned and used to DoS innocent websites on the other side. If you don't address this tradeoff you're not really engaging the issue. What I think we need is a professional, well-informed advocate of freedom who is willing to seriously discuss th…
There is no shortage of well informed advocates of freedom. The question is, which forum should they discuss this in? There is no meaningful forum for such a debate which will have any real effect on policy and that's by design.
The only place that can both debate and effect policy changes in the legislature and politicians will never take the people's side against corporations on an issue until they fear losing reelection.
Hence the ask to educate the people around you and to encourage them to reach out to their representatives.
Re: Hardware Attestation as Monopoly Enabler
#648Earlier quoted context omitted.
> Passkeys are better passwords. They need a TPM. Passkeys absolutely do not need TPM. You can get passkey support in any browser with a simple 1password plugin without any TPM hardware. The same way you could get a TOTP app on your phone without any TPM. TPMs are just an extra security layer for most usages. They are mainly a necessity for some shady business like DRMs.
> Passkeys absolutely do not need TPM. They do not, but how does the service you’re using know your passkey is secure? For all they know you’re just some gullible user that clicks through every fishing email you get. You’re dumb, weak, helpless, they gotta protect you from this scary world out there, and maybe yourself as well. They can’t do that if they allow your passkey to be stored anywhere you control. KeepassXC…
That's my business, not theirs. If my password gets stolen, that's my problem, not my bank's. Same deal if my passkey gets stolen. They're welcome to try to educate me on good security hygiene if they want, but what hardware I use to secure my credentials is not something they should get to decide.
Re: Hardware Attestation as Monopoly Enabler
#649The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…
Re: Hardware Attestation as Monopoly Enabler
#650Earlier quoted context omitted.
> You're not necessarily being surveiled just because you're forced to authenticate yourself. Oh hell you do! Google profit comes from ADS! It's for their profit to surveil and track and deanonymize TO SELL ADS.
Having thought about ads, what is the ideal feedback info channel loop from manufacturers to consumers? How best to distribute the information of who can manufacture what at what cost/price and what does it do and when is it appropriate for consumers to receive or pull info from where? And if it ends up being a monopoly of 1 centralized system how do you allow for a competitor to break through without ads?