Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

721–730 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#721

Earlier quoted context omitted.

> you present the same unblinded signature to both services You would never do this as it defeats the entire purpose of using blind signatures to begin with.

That's the point. You go to example.com and get the "sign in with Google" box as the only login option, but now you can't have separate uncorrelated Google accounts. Or if browsers do it automatically then every site does a background load or redirect through adtracker.nsa so you're presenting the same token on every service. It's not the user who wants any of this to begin with. "You would never do that" except that…

If A adopts a Blind Signature scheme it implies A is cooperating in establishing privacy infrastructure. If A is so malicious that it would advertise a sound privacy system and then it immediately sabotages it that's a different matter...

Re: Hardware Attestation as Monopoly Enabler

#722
post #234

Earlier quoted context omitted.

DRM is arguably a specific use of various generic technology ranging from whitebox cryptography to trusted computing. I don't think remote attestation (or even more so its umbrella technology, trusted computing) is nearly as specifically targeted as DRM. > We have over 30 years of the world wide web and for these more than 3 decades this was never a problem. Suddenly, we "need" to create new technology that seem to b…

>I still don't think this somehow outright disqualifies the technology itself. A technology squarely and 100% percent intended to give people other than the end user the ability to sleep soundly at night knowing those dastardly end users can't muck with their software (the non-end user) on their (the end user's) devices is only a tool for the authoritarian minded. Sorry mate, but if you're sitting here thinking it's…

> Show me an industry that ships source code, and manuals with all software that runs on the device, along with hardware manuals and the manuals to write your own drivers and doesn't use hardware primitives to enforce their business models over you, then we can talk

Here you go: https://puri.sm/products/librem-5

(And indeed, their Pureboot with Heads and a hardware key allow to restrict which OS can be booted on laptops, while not restricting the user.)

Re: Hardware Attestation as Monopoly Enabler

#723
post #693

Earlier quoted context omitted.

Apple is the classic “good king”. By and large they have used their power in ways that benefit users. Other than enriching apple, there’s been no direct or apparent harm to the end user from the walled garden. I know that is a controversial point, but harms we don’t ever know about are pretty hard to get upset about. But the “good” king never lasts. They’re always eventually replaced by a despot, and all the power yo…

Please explain what makes them good? They make a better product than most, but they also charge more than most. That's just a business model.

In this case i am using “good” to mean “not actively hostile towards users”. Yes they are more expensive, but many people are happy to pay a premium to get a premium product. Like going to a fancy restaurant and getting good food. Google’s version is like going to a less-fancy restaurant and getting less-good food but also they sell photos of you eating to TMZ.

Re: Hardware Attestation as Monopoly Enabler

#724

Earlier quoted context omitted.

> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged

Because Apple always did this, everybody knew this and people buy Apple exactly because of this. Google now pulls the rug on Android which is a whole different story because it used to be open. The whole idea of Android was to be open.

this is that xkcd "regular people can only name a few common feldspars" meme. over 90% of consumers have no knowledge at all of tech corps' philosophy on user freedom, they just buy cheap phones that have good cameras and run instagram and tiktok well.

Re: Hardware Attestation as Monopoly Enabler

#725

Earlier quoted context omitted.

>How about being banned from online banking, government services and all social networking / communication platforms? You aren't banned. You just have to use a secure device. It's like saying that a store banned you because they stopped taking checks and started requiring a credit card since they are more secure and harder to commit fraud with. As a person you didn't lose any freedom. Freedom does not mean someone ha…

> You just have to use a secure device. No, you have to use government backdoored device. I.e. the most secure android rom (at least the only rom we know is not penetrable by state-sponsored celebrite based malware) is not covered by google's play protect, while bunch of outdated CVEd phones are. Same will go with many hardened Linux machines, QubesOS, Whonix stations, you name it. I'd argue they are far more secure…

>QubesOS, Whonix stations, you name it. I'd argue they are far more secure than any average windows/macos installation.

OK, then let's see you argue it.

Most of the people who claim Linux is more secure have simplistic one-sentence arguments (e.g., "Linux is open-source, and many eyeballs make bugs shallow including bugs that are security holes") whereas those who say that MacOS and ChromeOS are more secure go into great technical detail as to why they think that.

Re: Hardware Attestation as Monopoly Enabler

#726

Earlier quoted context omitted.

> Passkeys absolutely do not need TPM. They do not, but how does the service you’re using know your passkey is secure? For all they know you’re just some gullible user that clicks through every fishing email you get. You’re dumb, weak, helpless, they gotta protect you from this scary world out there, and maybe yourself as well. They can’t do that if they allow your passkey to be stored anywhere you control. KeepassXC…

> how does the service you’re using know your passkey is secure That's my business, not theirs. If my password gets stolen, that's my problem, not my bank's. Same deal if my passkey gets stolen. They're welcome to try to educate me on good security hygiene if they want, but what hardware I use to secure my credentials is not something they should get to decide.

On principle I agree with you. And for me I totally want that, in part because I know how to take care of myself and avoid phishing (I got pwned once, but thankfully it was my company’s honey pot, not actual phishing).

Many people aren’t like us. Give them freedom to chose their password without mandating 2FA, and some will lose money to a password database leak & offline guessing. The policy maker knows this, at which point they have a choice: stricter annoying rules with fewer victims, or looser rules with more victims?

Yes, we can mitigate much of this with education, as can we limit vendor lock-in by mandating that the bank does not require any particular device they do not themselves distribute, for free, to their users. (My bank for instance gave me a little device that has a camera, a small screen and a key pad. Upon payment I use the device to scan some QR-code, the device gives me a one-time code that I type, and done.) My point is, some kind of tradeoff remains.

Also banks kinda have to deal with fraud, which presumably costs them money. Stolen passwords mean more fraud, increased costs… that may be incentive enough to enforce stricter rules. And to be honest I’m okay with that, as long as it is accessible. Which in my case means no phone app of any kind.

Come to think of it, there is one law I would pass: for important stuff like banks, no amount of security justifies a lack of accessibility. If I don’t have a smartphone, I should still be able to do online payments. Same if I’m blind. Or both. When I hear all around me about people being utterly unable to do banking, or worse, accessing government online services, without a locked down Android or iOS phone, I’m horrified.

Re: Hardware Attestation as Monopoly Enabler

#727
post #252

Earlier quoted context omitted.

Neither examples are evidence of corruption. That doesn't mean they're not problematic, but there's no evidence here of a politician receiving a kickback for any of these actions.

https://fortune.com/europe/2023/09/26/thorn-ashton-kutcher-y... $600K+ went to kickbacks, er… “lobbying”, and thorn was hit with some pretty nasty scandals involving sex crimes.

That's my point though, conflating lobbying and corruption doesn't help. Both are indeed problematic, but unlike actual corruption lobbying can be countered with activism.

Re: Hardware Attestation as Monopoly Enabler

#728
post #212

Earlier quoted context omitted.

What even is the problem? I keep my kids computers in the living room where it's easy to see what they are doing. Their lan shuts down at night when I'm asleep. They don't get full control of their own cell phone until they are around 16-years old. Bots on social media discourage me from using it which is a Good Thing if you ask me.

The problem is that companies have a legitimate reason to want to block AI agents and verify the users are actually real. And it's incredibly difficult to do that when the old methods of clicking on squares or reading blurry words don't work anymore. Solving proof of humanity is very difficult without tying to some kind of difficult to replicate or automate ID.

> The problem is that companies have a legitimate reason to want to block AI agents and verify the users are actually real.

Sucks that they have a hard problem like that. Taking away everyone's freedom to exercise ownership of their general purpose computing devices and destroying online anonymity shouldn't be the answer (or, at least, we shouldn't stand for it). Maybe they can spend some of their billions in revenue on it.

Re: Hardware Attestation as Monopoly Enabler

#729
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

There is a tradeoff between the freedom users have on their devices on one side, and the likelihood less sophisticated users will get their information stolen or their devices pwned and used to DoS innocent websites on the other side. If you don't address this tradeoff you're not really engaging the issue. What I think we need is a professional, well-informed advocate of freedom who is willing to seriously discuss th…

[deleted]

Re: Hardware Attestation as Monopoly Enabler

#730

Earlier quoted context omitted.

> I agree. They don't want to. That's not what the parent was saying. Most people don't have any opinion whatsoever on sideloading. You can go confirm this for yourself by asking a Mac or PC owner how scary it is. Most of them will respond that they genuinely never thought about it, not that they're afraid to consider it. To these people, it's a normal feature of their device that you could never remove. The parent i…

I do talk to computer users and they do fear making installations. Many of them have installed something that was adware or a virus, often without meaning to and regretted the results. I have been helping my family and extended family members fix their errors for a long time. This pushes them to big names with names to spoil. I suspect that the GP is, as you write, lamenting the lack of attention to the topic. > This…

> the app was removed the day after that post was made

LastPass has been downloaded in excess of 50 million times in the past 10 years. As many as 10,000 users could have installed the app and turned over their credentials to the trojan version in a 24 hour period. If your manual review takes a day to respond, it's already too late at Apple's scale.

> That is exactly why people feel more comfortable using the app store.

Then why does the App Store represent the minority of software sales on platforms like macOS, where users are given free reign to download whatever they want? It seems like users are overwhelmingly uncomfortable sticking to the App Store, if you take their actions and spending into account.

Apathy seems to be the best explainer here. Users don't care about security at all, they are just consuming whatever is put in front of them. That's why social engineering like LastPass works, and it's why you see people ignore systemic backdoor efforts like Client Side Scanning and Push notifications. They might be afraid of getting hacked, but it's plainly clear that none of them care enough to make a change in their lifestyle.

Post reply on HN