Earlier quoted context omitted.
You'll likely be ushered to their mobile app instead.
I don't do mobile apps. What I'll do instead (and, honestly, this is what I already mostly do anyhow so it's not really a sacrifice) is physically go to the bank branch to conduct my business.
Your computer should say what you tell it to say
131–140 of 263 posts
Re: Your computer should say what you tell it to say
#132I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…
> Once it exists though, you can be sure it will become a standard practice requirement Yes, this seems inevitable. At which point, I will no longer be using the bank's website. > they'll seem absurd and won't last long in that position. I'm not sure what you mean here, though. People who object to ubiquitous surveillance don't seem absurd to most (even those who aren't so upset about it), and they certainly aren't c…
Re: Your computer should say what you tell it to say
#133I agree with most of this, but one nit pick: > Originally, secure computing relied on a second processor - a "Technical Protection Module" or TPM - to monitor the parts of your computer you directly interact with. TPM stands for Trusted Platform Module, not Technical Protection Module
The EFF are known for their alternate expansions at times. By far not as bad as the FSF, but they do tend to editorialize. This however, absolutely sounds like someone being snarky.
Re: Your computer should say what you tell it to say
#134Earlier quoted context omitted.
I don't do mobile apps. What I'll do instead (and, honestly, this is what I already mostly do anyhow so it's not really a sacrifice) is physically go to the bank branch to conduct my business.
I don't know about your country but here the only people who physically go to the bank are 80+ grannies and granddads who think they're too old to learn this bloody computer stuff, and who are also willing to pay exorbitant 10-30 monetary units for each bill paid by a physical person in the physical bank, and to do even that they must accept that it's ok if you have to book an appointment at the bank's counter in adv…
I don't pay my bills at a bank or bank website regardless, there is no surcharge for going to a bank's physical location, and I don't have to make an appointment.
And people who go to branches aren't exclusively elderly and/or technophobes -- but even if they were, what does that matter?
Re: Your computer should say what you tell it to say
#135I think a realistic description/story from real experience I've had as a security engineer might help some people understand why this will end up so bad. I've worked with banks, who are among the most security-minded of organizations. It's not because they're security nerds, it's because the cost of getting hacked is astronomical, and because regulations require them to be "as secure as possible." Banks won't be chom…
my experience with banks has been the opposite - they're always a ways behind the rest of the web on security measures. some banks are still rolling out 2fa. and look how horrifically insecure credit cards are. not because they don't care, but because they see technical measures as only a small piece of their overall security strategy, and online access as only a small part of their business that they consider untrus…
Re: Your computer should say what you tell it to say
#136Earlier quoted context omitted.
That's wild. It seems these blog posts are outsourced. Edit: I'm wrong about this one. It's an actual article, and a pretty good one at that. But it is either a mistake or they are introducing an alternate expansion for TPM (other acronyms have been given different sets of words).
I'm guessing it's an alternate expansion that was popularized by some group who was deeply doubtful about this technology. "Trusted Platform Module" sounds good . But what it actually means is that the platform can be "trusted" to place the interests of third parties over the owner of the device. Stallman referred to it as a "Treacherous Platform Module" because he saw it as betraying the user. I'm guessing that "Tec…
Re: Your computer should say what you tell it to say
#137Earlier quoted context omitted.
> Once it exists though, you can be sure it will become a standard practice requirement Yes, this seems inevitable. At which point, I will no longer be using the bank's website. > they'll seem absurd and won't last long in that position. I'm not sure what you mean here, though. People who object to ubiquitous surveillance don't seem absurd to most (even those who aren't so upset about it), and they certainly aren't c…
Given that most people don't use ad blockers, I suspect most people will not stop using the website, at which point, it becomes safe to assume most people will have a browser it works with. Once that point is reached, there's no reason it wouldn't proliferate to any number of sites, including ones you likely do use.
> Given that most people don't use ad blockers
In the US, 40% of people do use ad blockers. That's certainly not "most", but it is a large enough number to be significant.
Re: Your computer should say what you tell it to say
#138I mean, devil's advocate here, this tech already exists and the question is do we do client attestation in a browser or pretend remote attestation doesn't exist. If this gets rejected, would that mean that services that need a "trusted client" simply deprecate their web apps and rely on a iOS/Android app? I'm not trying to argue in favor of WEI, I just think this doesn't magically disappear if Google doesn't implemen…
They will ship this, standard or not. But I don't see a reason for Apple to ship this in Safari, or Firefox neither. So I expect this will be a real test of Chrome's market power. Will any sites start blocking non-WEI browsers? Locking out iPhones seems insane. Or will we see differential ad rates for WEI environments?
Re: Your computer should say what you tell it to say
#139>You can choose not to send this to the remote server, but you lose the ability to send an altered or randomized description of your device and its software if you think that's best for you. The EFF is being misleading here by conflating the attestation taken and fingerprintable information like a user agent. An attestation taken does not contain information about the device that can be used to identify since the dat…
Re: Your computer should say what you tell it to say
#140Earlier quoted context omitted.
> Once it exists though, you can be sure it will become a standard practice requirement Yes, this seems inevitable. At which point, I will no longer be using the bank's website. > they'll seem absurd and won't last long in that position. I'm not sure what you mean here, though. People who object to ubiquitous surveillance don't seem absurd to most (even those who aren't so upset about it), and they certainly aren't c…
> I will no longer be using the bank's website That's a great temporary measure, but once this has rolled out everywhere and is part of standard commercial experiences, are you really willing to completely opt out of online banking because you're not permitted to send fake browser identification? It's a fine philosophical position, but it feels akin to refusing to use public streets because of the existence of survei…
Attestation requirements from banks would mean I must run an OS with adware and spyware built in to use online banking. It's not (just) about browsers.