Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

731–740 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#731
post #529

Earlier quoted context omitted.

What I find ridiculous is to strongly believe that politicians are somehow all the same person, and therefore either all corrupt, or all fascists, or all... In a functioning democracy, politicians represent the people. Meaning that some politicians will be on one end of the spectrum, and some will be on the other. If there are no politicians you disagree with, then probably you are not living in a functioning democra…

> What I find ridiculous is to strongly believe that politicians are somehow all the same person, and therefore either all corrupt, or all fascists, or all... That's a distraction from the point that I actually made. One can try to paint politicians as saints all they want, and it still won't change the fact that the entire population is digitally surveilled 24/7 and what we do on our own computing devices are increa…

> it still won't change the fact that the entire population is digitally surveilled 24/7

I agree that we are, I disagree that we are because all politicians are corrupt. Surveillance capitalism is the result of the private companies that built it, who could because they became so big, because of the lack of antitrust and stuff like the DCMA (and the equivalent that the US forced every other country to adopt).

Did all politicians collude in order to get there? I don't think so. The fact is that many people thought it was great to have powerful US companies taking over the world.

> It's boilerplate fallacious logic that makes any criticism against anything sound illegitimate.

I don't think so. You are saying "they must be corrupt, otherwise they would agree with me". I say that it sometimes happens, in all good faith, that other people don't agree with you. They may have different opinions, or they may be uninformed, incompetent, or simply wrong. There are many, many reasons to disagree that are not corruption.

You gave Snowden as an example: most politicians were not aware of what the NSA was doing. I think only the President (and maybe someone else) did, outside of the NSA.

People who say "the politicians want X" don't understand how politics works. Especially in the EU, where they are elected by the people of 27 very different countries.

Re: Hardware Attestation as Monopoly Enabler

#732

Earlier quoted context omitted.

We just don't know much about one another. I never really thought about it until I saw this comment: https://news.ycombinator.com/item?id=45993140

Unfortunately, each European country has a different "national" payment method. Swish in Sweden, MobilePay in Denmark/Finland, iDEAL in the Netherlands, etc. Of course you can't sign up to a specific country payment system if you're not a resident there. And systems from different countries don't work with each other. Luckily, there's now an initiative called EPI [1], which is an alliance that wants to make all these…

PayPal, lightweight?!

Re: Hardware Attestation as Monopoly Enabler

#733
post #223

Earlier quoted context omitted.

The local models are still centralized and proprietary. They are basically closed source software.

Is there a way to make a model more open source than open weights?

You open the training data and the tools used to train it.

Re: Hardware Attestation as Monopoly Enabler

#734

Earlier quoted context omitted.

I do talk to computer users and they do fear making installations. Many of them have installed something that was adware or a virus, often without meaning to and regretted the results. I have been helping my family and extended family members fix their errors for a long time. This pushes them to big names with names to spoil. I suspect that the GP is, as you write, lamenting the lack of attention to the topic. > This…

> the app was removed the day after that post was made LastPass has been downloaded in excess of 50 million times in the past 10 years. As many as 10,000 users could have installed the app and turned over their credentials to the trojan version in a 24 hour period. If your manual review takes a day to respond, it's already too late at Apple's scale. > That is exactly why people feel more comfortable using the app sto…

I would have expected Apple to catch that on review. That was a egregious failure and betrayal of trust on their part. I wonder if they took any responsibility for the consequences of their error.

I'd agree if you wrote that most users don't understand security at all, that users aren't really given the tools they need to maintain security, or that exploits are designed to target people's vulnerabilities. You seem to be blaming the victims of motivated (sometimes) advanced actors. Even serious engineers have been phished for NPM publishing access.

Re: Hardware Attestation as Monopoly Enabler

#736
post #304

It seems to me that comments here are reading this as saying attestation is bad, when the real argument is that attestation should explicitly provide a path of inclusion for non-Apple and Google providers. The headline seems to make the statement that Apple and Google are evil and doing this for monopoly lock-in, and GrapheneOS, a competitor, will stand for the people against that. But given their final counterpoint…

The position of GrapheneOS is that attestation shouldn't be used to restrict people to an allowlist of hardware and operating systems. It can be used to without forbidding them from using what they want to use. However, if it's going to be used to make an allowlist of hardware and operating systems, then it needs to permit any any at least as secure as what they're permitting to be approved. Instead, they're enforcing Google's business model for licensing Google Mobile Services while not requiring secure devices at all. There's no security value in the current Play Integrity API which permits devices with no patches for 10 years.

Even the Play Integrity API strong integrity level only enforces being no more than 1 year behind on the official Android security bulletins which are 3-4 months outdated at release so that's nearly a year and a half behind of patches. It also has the massive loophole of permitting being arbitrarily behind on patches for earlier Android versions than Android 13, so even the strong integrity level permits a device launched with Android 8 with no patches applied since then. That's not a security check, it's a business model check to lock out alternatives not licensing Google Mobile Services. The licensing terms for Google Mobile Services have been found to be illegal in multiple countries. Google enforcing agreeing to those terms with the Play Integrity API is a truly extraordinarily violation of antitrust laws. Governments are not only failing to act but adopting it themselves. It's going to be looked back on as a massive failure for technology regulation/legislation along with government tech policy beyond that.

Re: Hardware Attestation as Monopoly Enabler

#737

Ironically, the other top article on HN right now is CVE-2024-YIKES. You can't have the cake and eat it too. Maybe we need to close some doors, especially if the barrier for publication is literally just a couple of prompts and uploading the result to distributor like npm or play store.

You can't have the cake and eat it too. One of our Founding Fathers said it best (I know the original context was different, but it fits so well with the current theme): "Those who give up freedom for security deserve neither." Also, "the optimal amount of crime is nonzero."

https://xkcd.com/1357/

I think you are conflating free speech with right to a platform and distribution. Which isn't quite a right, or at least not as constitutional, the former is about not obstructing speech, the latter is about positively enabling it.

One of the key aspects of distribution is cost. You can pay for a domain, which is 15$/yr, and a host (which can be as cheap), and distribute your software that way. Since when did we agree that randoms have right to publish software, and vanish? (And why are 'we' using such code in production with a straight face?) The internet founding fathers wisely designed Domain names, DNS, ICANN, HTTP, TCP, IP, NICs. NPM is not in that echelon, NPM is gratis, not freedom.

Also, freedom is, unless you are a libertarian a patriot or a nation, a historical concept, not irrelevant, but definitely a concept that was born out of a different time (slavery, secession), in its modern american sense, it's most definitely not gratis-adjacent.

To reference a specific American Freedom, in order to have access to justice, you have to pay court fees, and an attorney, there's mechanisms in place to waive those fees or have a public defender, but not even America's modern freedom developed a secondary system which pretended to have no cost, and if it did (private lateral arbitration).

I guess private entities have the right to offer public services by proxy, like with subdomains, github pages, vercel, npm packages. But I wouldn't call that freedom, in essence, the cake you can't have and eat in this case is Freedom and Gratis. You either pay the minimum costs established by the public system, or use a gratis non-free system to distribute your 'speech'.

And we the users, have the right to ignore the gratis spam and demand some sort of PoW for messages.

The system works

Re: Hardware Attestation as Monopoly Enabler

#738
post #731

Earlier quoted context omitted.

> What I find ridiculous is to strongly believe that politicians are somehow all the same person, and therefore either all corrupt, or all fascists, or all... That's a distraction from the point that I actually made. One can try to paint politicians as saints all they want, and it still won't change the fact that the entire population is digitally surveilled 24/7 and what we do on our own computing devices are increa…

> it still won't change the fact that the entire population is digitally surveilled 24/7 I agree that we are, I disagree that we are because all politicians are corrupt . Surveillance capitalism is the result of the private companies that built it, who could because they became so big, because of the lack of antitrust and stuff like the DCMA (and the equivalent that the US forced every other country to adopt). Did al…

I brought up the Snowden disclosure because it's significant. What governments along with the tech sector did behind our backs is a major violation of human rights and undermines the very foundations of the rule of law. After Snowden, politicians have no plausible deniability. We were all made aware what the consequences of our policies are, and it's only getting worse. Yet, instead of dismantling these illegal programs all together, politicians continue to expand its scope with laws like we're discussing here.

According to the dictionary, corruption is "dishonest or illegal behavior especially by powerful people (such as government officials or police officers)." If this isn't corruption, I don't know what is.

https://www.merriam-webster.com/dictionary/corruption

Also,

> I disagree that we are because all politicians are corrupt.

I repeat, I never said this. There are politicians like Ron Wyden or Bernie Sanders that oppose digital surveillance and control.

Re: Hardware Attestation as Monopoly Enabler

#739

Earlier quoted context omitted.

Closed or open source doesn't matter; it's the ability to control them that's important. People have been cracking and patching for decades without source, but they have that control. Contrast this with remote attestation, where they might show you the source code for everything but you're still powerless to do anything.

> Closed or open source doesn't matter; it's the ability to control them that's important. People have been cracking and patching for decades without source, but they have that control. You have no idea what has been baked into the weights in the training process. In theory you could find biases and attempt to "patch" them out, but its a vastly different process vs. patching machine code. Consider what would happen i…

There are a ton of methods to probe training data from a trained model, both for open and closed-source models.

Re: Hardware Attestation as Monopoly Enabler

#740
I don't think the govt should be able to set rules that limit and control adult's freedoms with computers.

I don't think the govt should be able to set rules that limit and control children's freedoms with computers.

A child can't enter a nightclub or a liquor store. The closest digital equivalents are basically permanently available to them though.

Post reply on HN