Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

671–680 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#671

Earlier quoted context omitted.

I feel like the complaint about this not adding to security could be read in a really wrong way. Instead of "this is some hypocritical BS", could be interpreted as "lol let's lock EOL devices from even lower integrity tiers". Doubt this is possible because so, so many people use EOL phones, but still.

Doubt this is possible because so, so many people use EOL phones, but still. Because many people have fortunately realised that "EOL" is just an excuse to create lots of e-waste and push even more hostile unwanted changes.

I would attribute EOL phone use to largely to being frugal or poor. I'm sure at least one person considers the ecological factor but I'd expect that to be a small cohort.

Re: Hardware Attestation as Monopoly Enabler

#672
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

Is there a good primer on why this is bad? I know that it is on a technical level. But I havent heard anyone talk about in layman's terms Maybe I'll need to write something up. But it be great to have some resources as to why this is bad from a perspective other than my own.

I'm doing a presentation on Surveillance Capitalism soon and I might include this topic.

Re: Hardware Attestation as Monopoly Enabler

#673

Earlier quoted context omitted.

This reminds me of crypto wallets. I also dispute mike_hearn 's: > Smartphone HW attestation is better in every way They're still prone to side-channel attacks like SPECTRE. Crypto wallets are practically immune because they're air-gapped. [edit] I just realised that's Mike Hearn of early BTC fame. I suppose he would know what a crypto wallet is.

Spectre doesn't work across process boundaries, so I don't think they are. You can't Spectre your way into a banking app on an iPhone. Or if you can I'd like to see it in action.

I don’t think "Spectre doesn’t work across process boundaries" is correct as stated; cross-process and cross-security-domain Spectre attacks have been demonstrated. But I agree that "a malicious app can trivially Spectre its way into an arbitrary banking app on a patched iPhone" is a much stronger claim, and I’m not aware of a public demonstration of that exact attack. My point is only that process isolation alone is not, in principle, a complete answer to Spectre-class attacks.

Re: Hardware Attestation as Monopoly Enabler

#674

Earlier quoted context omitted.

The biggest mistake is that people trusted a company that, in reality, isn't that different from Apple. Just because everyone claimed Android as the true open source alternative to iOS, when only AOSP was that.

Yea agree. I reeeeally dont get why Google or Apple have good reputation at all.

i mean Apple kind of used that position for building a good reputation. their whole thing is/was how secure their devices were and how they had human verification on all apps that went through the app store with a clear intents file (a file the describes exactly WHY an app needs permission for bluetooth/etc), and a secure enclave that prevented even the FBI from getting in (while apple refused to give them a backdoor). Hackers and tinkerers will find a lot of these measures to be an annoyance and authoritative control, but a lot of people just want their phone to a product, not the user.

Re: Hardware Attestation as Monopoly Enabler

#675

Earlier quoted context omitted.

This. Plus if I want to access my bank account on a device I trust , the bank shouldn’t say “hey we don’t trust it so buzz off”. It’s my money in that account. I understand there’s some stupid compliance thing that makes banks do this, but it clearly isn’t a hard requirement, as there’s still plenty of banks that don’t participate in this security theatre.

To be fair to your bank, it has to cover you if your money gets stolen through a hack through their app, no matter what your operating system is.

I’d very much love to have an option to waive that cover though! Just give me a scary warning “hey, we’ve determined your device is unsafe; so if you get hacked through that device, you agree not to hold us liable for that. proceed? [y/N]”

For more specific mitigations, they could issue shorter-living tokens to such devices, in case it gets stolen and it didn’t store the token properly (say, the user did something stupid like “hey I’ll substitute secure enclave with a shim that writes secrets to an SD card”). And they could limit certain critical functions that do require attestation for some reason (e.g. Host Card Emulation, aka “tap your phone to pay”, which they usually delegate to Google Wallet/Pay/Wallet anyway).

Wise seems to do it correctly. It works on rooted phones, even, just gives a scary warning and blocks some app functions. They also have a fully functional webapp, so you mostly don’t need the app anyway. Revolut, on the other hand, has outright blocked me from my account – so I’m not using it anymore.

Re: Hardware Attestation as Monopoly Enabler

#676

Requiring authorized silicon (and software) isn't even the biggest problem here. They do not use zero knowledge proof systems or blind signatures. So every time you use your device to attest you leave behind something (the attestation packet) that can be used to link the action to your device. They put on a show about how much they care about your privacy by introducing indirection into the process (static device 'ID…

> Requiring authorized silicon (and software) isn't even the biggest problem here.

I agree, except I worry it's a bigger concern than we realize.

I still remember what CableCard (and the hoops needed for HW manufacturers to get certified) did to the DIY DVR Market...

Re: Hardware Attestation as Monopoly Enabler

#677

Earlier quoted context omitted.

> You don't have to compromise anything. So… I don’t have to compromise the ability to run any program I want on my machine, and I don’t have to compromise the ability to be root on my machine. Right? And of course, when I say "me", I’m talking about everyone, including cheaters. Meaning, we don’t have to compromise the cheater’s ability to run any program they want (that would include cheats), nor their ability to b…

>So… I don’t have to compromise the ability to run any program I want on my machine, and I don’t have to compromise the ability to be root on my machine. Right? Yes. You are free to do whatever you want on your machine. >Meaning, we don’t have to compromise the cheater’s ability to run any program they want (that would include cheats), nor their ability to be root on their machine. Yep. The only thing the cheater is…

> No I mean that the operating system protects applications from messing with each other. The operating system should isolate each app for security purposes.

Oh but that is far incomplete a specification. What security purposes? Who are we protecting, from whom? On whose behalf does the OS isolates applications from each other? If it’s on mine, then you bet I absolutely want the ability to lift that isolation in specific cases. It’s my computer, I decide when and how the rules are broken.

But the moment I have that (a computer and OS that really work for me), I lose the ability to prove that I don’t. If I play an online game, being in control means the game company is not, and I can’t prove to them I’m not cheating.

I’m not aware of any third alternative.

Re: Hardware Attestation as Monopoly Enabler

#678
post #669

Earlier quoted context omitted.

A least they would give money to something useful.

I think you miss my point: When bots can "give" more money/computing power, then the transaction is no longer a good test of being human.

This is why I said "at least".

Re: Hardware Attestation as Monopoly Enabler

#679

Earlier quoted context omitted.

You still suffer, because developers who don't want to pay the Apple tax on their apps simply avoid the App Store. You have no access to many good apps at all. Including FLOSS.

I don’t care about apps at all, I avoid them wherever possible. Web stuff is good enough for most things. That being said I won’t purchase an apple device again if this one croaks

Web apps are indeed better, unless you need an access to hardware, fast computation or similar. But Apple is against web apps, so you're right to abandon them.
Post reply on HN