Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

771–780 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#771
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

Petitions are also a good way of reaching out to people and explain the dangers of these issues. Many people that usually sign petitions are notified of new ones, and, as a generalisation, they are usually fairly against big tech.

If anyone knows of any european petition around this please share them with us

Re: Hardware Attestation as Monopoly Enabler

#772

With all of the discourse around hardware attestation, digital ID, and age verification in recent weeks/months, is there actually any good solution to the problems these existing tools (Privacy Pass, WEI, Fraud Defense, uploading IDs) claim to solve? Are there open and privacy-preserving standards that can solve the problem of bots and minors? If not, what would be required to establish one, and is it realistic? Busi…

There is a good solution to these problems. Exhaustive punishments and forcefully ceasing operations for repeat offenses.

China has all the tech giants jumping through whatever hoops they want by banning them by default and only allowing whichever ones they want to operate after they meet their strict policies and ad hoc decisions.

Now that the US has decided the EU is a rival, the EU should do the same.

Re: Hardware Attestation as Monopoly Enabler

#773
post #405

Earlier quoted context omitted.

Don't hardware identifiers also mean that Google can blacklist your device from vast portions of the internet whenever they feel like it?

Do we know whether this is possible? I'm clueless when it comes to phones, so this is a genuine question.

[flagged]

Re: Hardware Attestation as Monopoly Enabler

#774

Not to rain on the parade, but doesn't GrapheneOS only works on Google Pixel devices? I mean, that's still in the Google jail on a physical level, even if they swap out the software.

they made a deal with Motorola, from next year we should have an alternative. in any case, google started to cause issues with pixel 10, so it's not as easy to port it

> google started to cause issues with pixel 10

Google started causing issues over 20 years ago.

Re: Hardware Attestation as Monopoly Enabler

#775
post #271

What freedoms do we value ? freedom of speech, freedom of compute, freedom to own assets, to sell our work or give it away, bodily autonomy, freedom to travel, to read to learn ? Amid the massive hype of the Web3 Crypto era, there was a kernel of useful innovation : that you can choose to have unique digital copies of things, and thus you can have a way of sending value that bypasses the middlemen, be they local thug…

[deleted]

Re: Hardware Attestation as Monopoly Enabler

#776

Earlier quoted context omitted.

> how does the service you’re using know your passkey is secure That's my business, not theirs. If my password gets stolen, that's my problem, not my bank's. Same deal if my passkey gets stolen. They're welcome to try to educate me on good security hygiene if they want, but what hardware I use to secure my credentials is not something they should get to decide.

On principle I agree with you. And for me I totally want that, in part because I know how to take care of myself and avoid phishing (I got pwned once, but thankfully it was my company’s honey pot, not actual phishing). Many people aren’t like us. Give them freedom to chose their password without mandating 2FA, and some will lose money to a password database leak & offline guessing. The policy maker knows this, at whi…

> they have a choice: stricter annoying rules with fewer victims, or looser rules with more victims?

Yep, there's a reason freedom vs safety (or libertarianism vs authoritarianism) is an axis on many political spectrum charts. This is a very common source of tension in politics. As you can probably guess, I usually find myself on the libertarian side of such debates. Freedom is worth the price.

> Give them freedom to chose their password without mandating 2FA, and some will lose money to a password database leak & offline guessing

To be clear, I have no issue with secure defaults. There's only an issue when you start trying to make it impossible for users to compromise their own security, because accomplishing that requires you to take away their freedom to make choices, which I don't think is an acceptable thing to do to mentally sound adults.

There's plenty of competition in the banking space, so normally I'd be fine letting banks and their customers sort this out on their own. But there's not a lot of competition in the OS space, and allowing banks to limit your choice of OS exacerbates that problem.

The fix I've been floating in my head for some time now for a lot of these types of problems in the digital space is some sort of software freedom law guaranteeing users the right to modify software running on devices they own. It would fix so many issues with the software industry, including probably this one, since many common uses of hardware attestation would probably fall afoul of such a law.

Re: Hardware Attestation as Monopoly Enabler

#777

Earlier quoted context omitted.

> Are there open and privacy-preserving standards that can solve the problem of bots and minors? If not, what would be required to establish one, and is it realistic? Ideally there shouldn't be standards for this. What we have already is enough. Companies claiming they are closing down their services/devices to protect the users is total BS. Facebook has admitted they get 10% of their ad revenue from scams, and that'…

I disagree. Bots have always been an issue, but now every form of CAPTCHA that can be solved by a human can also be solved by a multi-modal language model. Bots are slowly taking over in forums where they previously would have been immediately spotted and banned. If the only argument you can make every time someone proposes an onerous, privacy-destroying solution to this problem is deny the problem exists, you're goi…

> Bots are slowly taking over in forums where they previously would have been immediately spotted and banned.

Failed to mention this but part of the reason for this is that even after getting past CAPTCHA and creating an account, spam bots in online communities have always had to pass a sort of informal ongoing Turing test to not get outed as a bot by human users and banned. In the past, that would happen almost instantly as soon as the bot posted anything. Now they can often go undetected by even human mods for a long time, maybe even indefinitely.

Re: Hardware Attestation as Monopoly Enabler

#778

Requiring authorized silicon (and software) isn't even the biggest problem here. They do not use zero knowledge proof systems or blind signatures. So every time you use your device to attest you leave behind something (the attestation packet) that can be used to link the action to your device. They put on a show about how much they care about your privacy by introducing indirection into the process (static device 'ID…

Can you revoke certificate for a specific device using privacy schemes? Like imagine that someone managed to extract key from the specific device and distributed that key in a software implementation to fake attestation. Now Google needs to revoke that particular key to disallow its usage. This is obvious requirement.

Yes, with blind signatures you still have a central authority which voluntarily 'launders' tokens for you. When you present it your certificate and ask it to give you a blind signature it can reject the certificate.

However if someone extracts a key and keeps it private, and instead gives out unblinded tokens there is nothing you can do other than rate limit - realistically, an adversary is going to trial different rates anyway to figure out which don't make them an outlier.

Re: Hardware Attestation as Monopoly Enabler

#779

Earlier quoted context omitted.

>So… I don’t have to compromise the ability to run any program I want on my machine, and I don’t have to compromise the ability to be root on my machine. Right? Yes. You are free to do whatever you want on your machine. >Meaning, we don’t have to compromise the cheater’s ability to run any program they want (that would include cheats), nor their ability to be root on their machine. Yep. The only thing the cheater is…

> No I mean that the operating system protects applications from messing with each other. The operating system should isolate each app for security purposes. Oh but that is far incomplete a specification. What security purposes? Who are we protecting, from whom? On whose behalf does the OS isolates applications from each other? If it’s on mine, then you bet I absolutely want the ability to lift that isolation in spec…

In short the integrity of the application must be secured. This integrity must be protected from everyone. Nothing should be able to violate the integrity of the app.

>I absolutely want the ability to lift that isolation in specific cases.

There is no need for this. Allowing end users to turn off security features is not a good idea. Users should not have to think about such things.

>I decide when and how the rules are broken.

Most users do not want this ability. They just want a computer that works and is safe to use. They don't want to dictate how exactly it was written. That is the manufacturers job.

Re: Hardware Attestation as Monopoly Enabler

#780

Earlier quoted context omitted.

I don't see any consumer nor developer demand to make cheating in multiplayer games an inherent tenant of a computing ecosystem. Attestation is just an optional feature that expands what is possible. Services have no obligation to check attestation or use it as a hard signal to block people. All previously existing freedom is still possible on your computer.

> Attestation is just an optional feature that expands what is possible. So optional that everything that can require it will require it. Games want it because cheating. Streaming services want it because piracy. Banks want it because fraud. Web sites want it because advertising. Governments want it because encryption and anonymity. > Services have no obligation to check attestation or use it as a hard signal to bloc…

If there is market demand to not require it then there still will be services that don't require it. If there is such little demand for it, is such a thing actually valuable to society?
Post reply on HN