Earlier quoted context omitted.
> you present the same unblinded signature to both services You would never do this as it defeats the entire purpose of using blind signatures to begin with.
That's the point. You go to example.com and get the "sign in with Google" box as the only login option, but now you can't have separate uncorrelated Google accounts. Or if browsers do it automatically then every site does a background load or redirect through adtracker.nsa so you're presenting the same token on every service. It's not the user who wants any of this to begin with. "You would never do that" except that…
Hardware Attestation as Monopoly Enabler
721–730 of 799 posts
Re: Hardware Attestation as Monopoly Enabler
#722Earlier quoted context omitted.
DRM is arguably a specific use of various generic technology ranging from whitebox cryptography to trusted computing. I don't think remote attestation (or even more so its umbrella technology, trusted computing) is nearly as specifically targeted as DRM. > We have over 30 years of the world wide web and for these more than 3 decades this was never a problem. Suddenly, we "need" to create new technology that seem to b…
>I still don't think this somehow outright disqualifies the technology itself. A technology squarely and 100% percent intended to give people other than the end user the ability to sleep soundly at night knowing those dastardly end users can't muck with their software (the non-end user) on their (the end user's) devices is only a tool for the authoritarian minded. Sorry mate, but if you're sitting here thinking it's…
Here you go: https://puri.sm/products/librem-5
(And indeed, their Pureboot with Heads and a hardware key allow to restrict which OS can be booted on laptops, while not restricting the user.)
Re: Hardware Attestation as Monopoly Enabler
#723Earlier quoted context omitted.
Apple is the classic “good king”. By and large they have used their power in ways that benefit users. Other than enriching apple, there’s been no direct or apparent harm to the end user from the walled garden. I know that is a controversial point, but harms we don’t ever know about are pretty hard to get upset about. But the “good” king never lasts. They’re always eventually replaced by a despot, and all the power yo…
Please explain what makes them good? They make a better product than most, but they also charge more than most. That's just a business model.
Re: Hardware Attestation as Monopoly Enabler
#724Earlier quoted context omitted.
> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged
Because Apple always did this, everybody knew this and people buy Apple exactly because of this. Google now pulls the rug on Android which is a whole different story because it used to be open. The whole idea of Android was to be open.
Re: Hardware Attestation as Monopoly Enabler
#725Earlier quoted context omitted.
>How about being banned from online banking, government services and all social networking / communication platforms? You aren't banned. You just have to use a secure device. It's like saying that a store banned you because they stopped taking checks and started requiring a credit card since they are more secure and harder to commit fraud with. As a person you didn't lose any freedom. Freedom does not mean someone ha…
> You just have to use a secure device. No, you have to use government backdoored device. I.e. the most secure android rom (at least the only rom we know is not penetrable by state-sponsored celebrite based malware) is not covered by google's play protect, while bunch of outdated CVEd phones are. Same will go with many hardened Linux machines, QubesOS, Whonix stations, you name it. I'd argue they are far more secure…
OK, then let's see you argue it.
Most of the people who claim Linux is more secure have simplistic one-sentence arguments (e.g., "Linux is open-source, and many eyeballs make bugs shallow including bugs that are security holes") whereas those who say that MacOS and ChromeOS are more secure go into great technical detail as to why they think that.
Re: Hardware Attestation as Monopoly Enabler
#726Earlier quoted context omitted.
> Passkeys absolutely do not need TPM. They do not, but how does the service you’re using know your passkey is secure? For all they know you’re just some gullible user that clicks through every fishing email you get. You’re dumb, weak, helpless, they gotta protect you from this scary world out there, and maybe yourself as well. They can’t do that if they allow your passkey to be stored anywhere you control. KeepassXC…
> how does the service you’re using know your passkey is secure That's my business, not theirs. If my password gets stolen, that's my problem, not my bank's. Same deal if my passkey gets stolen. They're welcome to try to educate me on good security hygiene if they want, but what hardware I use to secure my credentials is not something they should get to decide.
Many people aren’t like us. Give them freedom to chose their password without mandating 2FA, and some will lose money to a password database leak & offline guessing. The policy maker knows this, at which point they have a choice: stricter annoying rules with fewer victims, or looser rules with more victims?
Yes, we can mitigate much of this with education, as can we limit vendor lock-in by mandating that the bank does not require any particular device they do not themselves distribute, for free, to their users. (My bank for instance gave me a little device that has a camera, a small screen and a key pad. Upon payment I use the device to scan some QR-code, the device gives me a one-time code that I type, and done.) My point is, some kind of tradeoff remains.
Also banks kinda have to deal with fraud, which presumably costs them money. Stolen passwords mean more fraud, increased costs… that may be incentive enough to enforce stricter rules. And to be honest I’m okay with that, as long as it is accessible. Which in my case means no phone app of any kind.
Come to think of it, there is one law I would pass: for important stuff like banks, no amount of security justifies a lack of accessibility. If I don’t have a smartphone, I should still be able to do online payments. Same if I’m blind. Or both. When I hear all around me about people being utterly unable to do banking, or worse, accessing government online services, without a locked down Android or iOS phone, I’m horrified.
Re: Hardware Attestation as Monopoly Enabler
#727Earlier quoted context omitted.
Neither examples are evidence of corruption. That doesn't mean they're not problematic, but there's no evidence here of a politician receiving a kickback for any of these actions.
https://fortune.com/europe/2023/09/26/thorn-ashton-kutcher-y... $600K+ went to kickbacks, er… “lobbying”, and thorn was hit with some pretty nasty scandals involving sex crimes.
Re: Hardware Attestation as Monopoly Enabler
#728Earlier quoted context omitted.
What even is the problem? I keep my kids computers in the living room where it's easy to see what they are doing. Their lan shuts down at night when I'm asleep. They don't get full control of their own cell phone until they are around 16-years old. Bots on social media discourage me from using it which is a Good Thing if you ask me.
The problem is that companies have a legitimate reason to want to block AI agents and verify the users are actually real. And it's incredibly difficult to do that when the old methods of clicking on squares or reading blurry words don't work anymore. Solving proof of humanity is very difficult without tying to some kind of difficult to replicate or automate ID.
Sucks that they have a hard problem like that. Taking away everyone's freedom to exercise ownership of their general purpose computing devices and destroying online anonymity shouldn't be the answer (or, at least, we shouldn't stand for it). Maybe they can spend some of their billions in revenue on it.
Re: Hardware Attestation as Monopoly Enabler
#729The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…
There is a tradeoff between the freedom users have on their devices on one side, and the likelihood less sophisticated users will get their information stolen or their devices pwned and used to DoS innocent websites on the other side. If you don't address this tradeoff you're not really engaging the issue. What I think we need is a professional, well-informed advocate of freedom who is willing to seriously discuss th…
Re: Hardware Attestation as Monopoly Enabler
#730Earlier quoted context omitted.
> I agree. They don't want to. That's not what the parent was saying. Most people don't have any opinion whatsoever on sideloading. You can go confirm this for yourself by asking a Mac or PC owner how scary it is. Most of them will respond that they genuinely never thought about it, not that they're afraid to consider it. To these people, it's a normal feature of their device that you could never remove. The parent i…
I do talk to computer users and they do fear making installations. Many of them have installed something that was adware or a virus, often without meaning to and regretted the results. I have been helping my family and extended family members fix their errors for a long time. This pushes them to big names with names to spoil. I suspect that the GP is, as you write, lamenting the lack of attention to the topic. > This…
LastPass has been downloaded in excess of 50 million times in the past 10 years. As many as 10,000 users could have installed the app and turned over their credentials to the trojan version in a 24 hour period. If your manual review takes a day to respond, it's already too late at Apple's scale.
> That is exactly why people feel more comfortable using the app store.
Then why does the App Store represent the minority of software sales on platforms like macOS, where users are given free reign to download whatever they want? It seems like users are overwhelmingly uncomfortable sticking to the App Store, if you take their actions and spending into account.
Apathy seems to be the best explainer here. Users don't care about security at all, they are just consuming whatever is put in front of them. That's why social engineering like LastPass works, and it's why you see people ignore systemic backdoor efforts like Client Side Scanning and Push notifications. They might be afraid of getting hacked, but it's plainly clear that none of them care enough to make a change in their lifestyle.