Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

681–690 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#681

Earlier quoted context omitted.

Let's dig into what makes them worse, and see what we can do about it. I think the main struggle is moderation. Moderation requires a hierarchy, which is much more compatible with a centralized model. I'm thinking that curation would be a good alternative. Rather than authoritatively silencing unwanted content, just categorize it well enough for users to filter what they want.

I agree with you, but many people have yet to understand that content they disagree with will continue to exist, no matter what, and central gatekeepers are not helpful in eliminating that content. The fucking “nazi bar” analogy has ruined an entire generation. You would think after centuries of trying to stamp out competing ideas, humans would finally come to terms with the fact that it cannot be done . Small curate…

I don't think we have to argue against the "nazi bar" analogy, though. In that analogy, nazis are allowed to exist in the world, just not in the bar. The difference is how we implement the concept of "in". The same analogy works if you are out on the street: everyone is allowed to be there, but that doesn't give nazis the right to your attention.

Until we have a real way to meaningfully process natural language (I have a serious idea for that, but that's another conversation), we won't be able to automate content filtration. The next best thing is ironically similar to what we came here to complain about: attestations in a web of trust. If everything we bother to read is tied to a user identity (which can be anonymous), we can filter out content from any user identity that is generally agreed to be unwelcome. The traditional work of moderation can be replaced by collaborative categorization of both content and publishers. Any identity whose published content is too burdensome to categorize can simply be filtered out completely. The core difference is that there are no "special" users: anyone can make, edit, and publish a filter list. Authority itself is replaced by every participant's choice of filter. Moderated spaces are replaced by the most popular intersection of lists. Identity is verified by the attestation of other identities, based on their experience participating with you.

Re: Hardware Attestation as Monopoly Enabler

#682

Earlier quoted context omitted.

Speaking of ways to - rightly or wrongly - veer off on a tangent, and convince large numbers of people that the anti-Big Brother side is unhinged... A better counter argument to "catch the pedo" is to bring up cases of creeps who were insiders - law officers, or just techies with access - and used the "well-intended" tech to get at their victims.

> A better counter argument to "catch the pedo" is to bring up cases of creeps who were insiders - law officers Certainly. You mean like that time an Israeli Cyber Directorate division chief fled Nevada for Israel after being investigated for soliciting a minor for sexual purposes? https://www.haaretz.com/israel-news/2025-08-21/ty-article/.p... https://archive.is/kNYUo

Populations are large. You can draw a pattern in any population.

I think if I were saying this to convince people that hardware freedom is a good idea, they might think I care less about hardware freedom and more about memorising evil Israeli people to make sure I always have a negative example of an Israeli to mention in conversation.

Re: Hardware Attestation as Monopoly Enabler

#683

Earlier quoted context omitted.

The problem is not that the OS can’t attest the app is secure. The problem with cheating is that the game servers cannot attest the client is genuine in all aspects that matter: non-modified client, running in an environment where there is no inspection of its memory for map hacks, aim bots, and more. The only way to do that is a remote attestation of the entire chain: hardware, locked down OS, app. (If the OS isn’t…

The solution to cheating is what we used to have: moderated, privately owned servers, and invite-only servers. Let the cheaters join the cheat-friendly servers or the foolishly unmoderated servers.

I agree, but then you lose the convenience of centralised match making, and I’m guessing, a number of predatory monetisation schemes. Allowing third party servers however would be a very good way to stop killing games.

I don’t believe intrusive anti-cheating is required for online gaming to flourish. But even if it was, I would give up Elite Dangerous, for which I have bough a VR setup and build my cockpit, before I give up full control over my PC.

Re: Hardware Attestation as Monopoly Enabler

#684
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged

[dead]

Re: Hardware Attestation as Monopoly Enabler

#685
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

> If you want to make a meaningful contribution, however small, then make it a point to educate people about the control they are giving to large corporations like Google. This is a fool's errand. We live in a time without virtuous values, where convenience is king. The masses don't care about cookies or consent, they accept all. They only understand direct punishment.

>This is a fool's errand.

It is absolutely not. Awareness is what people need right now because nobody is saying anything different then the established line. The more people that put there voice into this, the better off we are going to be.

I'm hosting a Surveillance Capitalism Presentation soon that I designed myself, I'll likely post it on the net when I am done. If you are interested in hosting a zoom call or an in person awareness campaign like this. Email me from my website[0] campaign form[1] and ill notify you when its online and you can download it and use it yourself to host your own venue.

[0]: https://www.scottrlarson.com

[1]: https://www.scottrlarson.com/forms/form-contact-campaign/

Re: Hardware Attestation as Monopoly Enabler

#686

Earlier quoted context omitted.

> Closed or open source doesn't matter; it's the ability to control them that's important. People have been cracking and patching for decades without source, but they have that control. You have no idea what has been baked into the weights in the training process. In theory you could find biases and attempt to "patch" them out, but its a vastly different process vs. patching machine code. Consider what would happen i…

People are already patching these models using abliteration to prevent them from refusing any request, so it is possible for end users to change them in meaningful ways. You can download abliterated models right now from Hugging Face that will respond to all kinds of requests that frontier models refuse.

The problem is you can't reverse engineer what was baked into the weights because they are just weights. You'll never know if you've fixed everything because it's not always going to be as obvious as request refusal. It's also not binary where you can fully confirm something is fixed or if you've accidentally affected something else.

They're for sure impressive but I don't see how anyone can push them as "open" when they are literally binary blobs. Worse, because it's not practical for anyone to actually train LLMs that can even come close to competing with the ones corporations are pumping out.

Re: Hardware Attestation as Monopoly Enabler

#687

Earlier quoted context omitted.

I respectfully disagree with "they calculate in the fact of that lack of control into their purchase decision". The average person is not calculating anything but price, is it what everyone else is using, is it new etc. Very low level calculations. They aren't asking "can I install applications from outside the app store?". Etc.

Hrrm. It seems your original comment has been heavily edited. > They aren't asking "can I install applications from outside the app store?" I agree. They don't want to. They already can't begin to evaluate app trustworthiness and don't want to have to. And they shouldn't have to. Yet they live in a world where they do. So they lean on reputation, app store filtering, the legal system, and hope.

> I agree. They don't want to.

That's not what the parent was saying. Most people don't have any opinion whatsoever on sideloading. You can go confirm this for yourself by asking a Mac or PC owner how scary it is. Most of them will respond that they genuinely never thought about it, not that they're afraid to consider it. To these people, it's a normal feature of their device that you could never remove.

The parent is lamenting that people don't care about this technology - Client Side Scanning, hardware attestation, Push notification surveillance - all of it is enabled not because of fear, but apathy.

> And they shouldn't have to. Yet they live in a world where they do.

This is fearmongering logic that doesn't really defend the App Store. Putting your faith in a centralized software auditor also requires you to pay attention and stay abreast of scams. It's just a different exploit chain to deliver the same payloads: https://blog.lastpass.com/posts/warning-fraudulent-app-imper...

Re: Hardware Attestation as Monopoly Enabler

#688

Requiring authorized silicon (and software) isn't even the biggest problem here. They do not use zero knowledge proof systems or blind signatures. So every time you use your device to attest you leave behind something (the attestation packet) that can be used to link the action to your device. They put on a show about how much they care about your privacy by introducing indirection into the process (static device 'ID…

Ultimately, the point of hardware attestation isn't to ensure that your device is trusted, but that the action you're trying to perform was done by a human, not a bot doing millions of them per second. It's just another CAPTCHA mechanism in disguise, required because bots have gotten so good at solving the existing ones.

With a secure device, the only way to get an attestation for an account signup is to do the signup on that device, with real fingers clicking real buttons on a real screen. There's no way to short-circuit the process by automatically sending a JSON request and bypassing the actual signup flow from a Python script, like you can do with an insecure endpoint.

With blind signatures, a single compromised device destroys the value of the entire scheme, as it can be used to issue an infinite number of attestations with 0 human oversight.

What we need is a blind signature construction where the verifier can revoke a signature, each signature carries proof that none of the revoked signatures comes from the same signer, and where it is impossible for one signer to issue more than n distinct signatures during one time window. Not sure if this would be possible with ZKPs; my cryptography knowledge doesn't extend that far.

Re: Hardware Attestation as Monopoly Enabler

#689
post #6

Our civilization desperately needs a method to modify modern microelectronics after manufacturing that can be used at least in a well-equipped repair shop, and it needs it yesterday. Alternatively, just make it illegal to ship any kind of initial bootloader as part of a CPU's/SoC's mask ROM in any computing device that is marketed as a general-purpose one. I.e. the first instruction that the CPU executes after reset…

> Alternatively, just make it illegal to ship any kind of initial bootloader as part of a CPU's/SoC's mask ROM in any computing device that is marketed as a general-purpose one. Funny, I have a related proposal: make it illegal to sell hardware and distribute software. Or at least, if you distribute software, we don’t buy your hardware. The idea is to force hardware companies to release the complete user manual for t…

[dead]

Re: Hardware Attestation as Monopoly Enabler

#690
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged

Apple is the classic “good king”. By and large they have used their power in ways that benefit users. Other than enriching apple, there’s been no direct or apparent harm to the end user from the walled garden. I know that is a controversial point, but harms we don’t ever know about are pretty hard to get upset about.

But the “good” king never lasts. They’re always eventually replaced by a despot, and all the power you ceded to the “good” king falls into the hands of the bad king. Which is why ceding that power is a bad idea, and kings are a terrible system of government.

Post reply on HN