Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

751–760 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#751

Earlier quoted context omitted.

The problem is democracy and capitalism are incompatible, so that "if" is doing some really heavy lifting.

Why are they incompatible? They’ve been operating together for hundreds of years.

I think rather than "incompatible" the issue lies in equality/equity. Too many people are being manipulated.

Re: Hardware Attestation as Monopoly Enabler

#752
post #703

What I've failed to understand in this whole Google reCAPTCHA discussion so far: How is this is even going to prevent bot usage and increase security? What's going to stop a bot farm in SE Asia from running a fleet of Android devices?

It will certainly make some bot farms unprofitable: Remember that they are now paying for a screen, a battery, a 5G radio, software licenses, branding, distribution and customer support for which they have no use. Also consider this: While bot farms may be able to buy millions of Android devices, they will certainly attract a lot of scrutiny as they approach the billion mark. So bot farms will never own more Android…

Remember that they are now paying for a screen, a battery, a 5G radio, software licenses, branding, distribution and customer support for which they have no use.

If you have the $$$, which the big guys certainly do, they'll just buy the bare attestation bits and figure out how to use them directly.

Re: Hardware Attestation as Monopoly Enabler

#753
post #598

Earlier quoted context omitted.

> In other words, banks and governments and other such institutions have noticed (and they probably do have data to back this up) that very few of their customers use "unapproved" devices and a very large majority of fraud comes from "unapproved" devices. What would cause you to think that to be the case? There are two primary ways that bank fraud happens. The first is that the attacker steals the user's credentials,…

> Vandalism can be reduced by excluding fare evaders because that's a class of people rather than a class of devices. Just observing: People who don't own an iPhone or modern android are also, generally, of a class -- and probably one banks would prefer to not do business with for profitability reasons. People who don't have spyware/lockinware for principled reasons are currently rare enough to not matter in this ana…

> Just observing: People who don't own an iPhone or modern android are also, generally, of a class -- and probably one banks would prefer to not do business with for profitability reasons.

I don't know about that. There are plenty of retirees who want nothing to do with this "modern technology" while still having large amounts of retirement savings that the bank very much wants at their institution.

Small (and for that matter large) business owners also have a tendency to have complicated financial situations and correspondingly want to deal with them using a computer screen rather than a phone, and that's another class of customers banks are certainly not interested in driving away.

Meanwhile I take it you're implying that the people who don't have a smartphone to do banking on are undesirable poors, but those are the people who do use a phone for banking, because bargain bin Android phones are available for ~$15 and that's the extent of what they can afford for an internet device.

Whereas the people using the likes of GrapheneOS might well be a small percentage of the customer base but they're still generally the class of customers the banks like, i.e. tech people with upper middle class financial situations.

Re: Hardware Attestation as Monopoly Enabler

#754

Earlier quoted context omitted.

That's the point. You go to example.com and get the "sign in with Google" box as the only login option, but now you can't have separate uncorrelated Google accounts. Or if browsers do it automatically then every site does a background load or redirect through adtracker.nsa so you're presenting the same token on every service. It's not the user who wants any of this to begin with. "You would never do that" except that…

If A adopts a Blind Signature scheme it implies A is cooperating in establishing privacy infrastructure. If A is so malicious that it would advertise a sound privacy system and then it immediately sabotages it that's a different matter...

The proposals are generally to have the government do the blind signature scheme. But then even if they do so in good faith, the ad services will immediately set to work thwarting it.

Re: Hardware Attestation as Monopoly Enabler

#755
post #530

Earlier quoted context omitted.

I'm as biased against cryptocurrency as everyone, but couldn't we have the requestor do a bit of mining work to mint that initial id? I mean, if the service is actually making a bit of money from each request, the need for rate limiting just vanishes, right?

If proof of work is the "payment" to prove that you're human, many AI startups will outbid poor people living third world countries. They will even outbid some Americans. Yes, those AI startups can also buy cheap Android phones at scale, but it's a bit harder because they'll pay for stuff that their bots have no use for (a screen, a battery, a 5G radio, software, branding, distribution, customer support etc).

> If proof of work is the "payment" to prove that you're human, many AI startups will outbid poor people living third world countries. They will even outbid some Americans.

The difference is that if you're human you can create an account and then carry on using it for decades, whereas if you're an aggressive scraper bot or spammer then you get banned and have to buy new accounts over and over.

Re: Hardware Attestation as Monopoly Enabler

#756
post #574

Earlier quoted context omitted.

Frame it as "America will decide what you can do with your phone" and people in Europe will listen.

Frame it as "the government will decide what you can do with your phone" and people in America will listen.

Frame it as "won't somebody think of the children" and everyone will listen.

Re: Hardware Attestation as Monopoly Enabler

#757
post #693

Earlier quoted context omitted.

Please explain what makes them good? They make a better product than most, but they also charge more than most. That's just a business model.

In this case i am using “good” to mean “not actively hostile towards users”. Yes they are more expensive, but many people are happy to pay a premium to get a premium product. Like going to a fancy restaurant and getting good food. Google’s version is like going to a less-fancy restaurant and getting less-good food but also they sell photos of you eating to TMZ.

Is charging more money not hostile?

Re: Hardware Attestation as Monopoly Enabler

#758
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged

That's perhaps where the part about educating less tech-savvy folks comes in. There are even professionals in tech under the mistaken belief that Apple meaningfully adds value in exchange for one's freedom to use one's device as one chooses. Big Tech loves normalising the story how only they can help

Re: Hardware Attestation as Monopoly Enabler

#759
post #744
post #696

Earlier quoted context omitted.

For one thing, Apple has tended to focus on privacy at the expense of profit. Apple could certainly be monetizing all of their user data. Now more than ever. It's not just businesses that want your data to sell you stuff, it's the hyperscalers wanting to funnel it into AI training. Apple is not perfect, by any means. I recently had a conversation with a former Apple employee about how they employ differential privacy…

>For one thing, Apple has tended to focus on privacy at the expense of profit. A company reveals its priorities when it is forced to make inconvenient choices. What privacy compromises did the CCP force out of Apple in exchange for doing business in China?

Probably the same ones the US forced out of apple with PRISM

Re: Hardware Attestation as Monopoly Enabler

#760

Earlier quoted context omitted.

In this case i am using “good” to mean “not actively hostile towards users”. Yes they are more expensive, but many people are happy to pay a premium to get a premium product. Like going to a fancy restaurant and getting good food. Google’s version is like going to a less-fancy restaurant and getting less-good food but also they sell photos of you eating to TMZ.

Is charging more money not hostile?

Idk do you consider luxury cars “user-hostile”? Nice restaurants? Tailored clothing?
Post reply on HN