I was there, 3000 years ago, when we started ringing the bell about “trusted computing”. Honestly it’s not as bad as I expected
> it’s not as bad as I expected yet :D
What happened to running what you wanted on your own machine?
281–290 of 315 posts
Re: What happened to running what you wanted on your own machine?
#282Earlier quoted context omitted.
> and it's a question of "when" not "if" major sites start requiring it in the name of "safety" from bots. I recently found a plugin that can alert to JS doing shady "fingerprint-like" activity. I did not expect it to go off quite as often as it does now. It would seem that some sites are already asking _very_ probing questions about the browser so it's only a matter of time before they go one step further and demand…
Would you mind sharing a link to that plugin?
Sure thing!
https://jshelter.org/ is the homepage.
Re: What happened to running what you wanted on your own machine?
#283Earlier quoted context omitted.
Won't matter. Remote hardware attestation means they will know you're trying to bypass their control. You'll be denied service at every turn. Can't even log into your bank account.
IMO, I don't see how remote hardware attestation avoids being spoofed. Yes, TPM is involved, but the end of the day, it's an API request/response. There are so many ways the request could be spoofed, and the attestation likely requires coordination with hardware vendors that have proven to be Highly Secure TM with the history of secure boot leaks.
The fact that you can make it pass in some cases using Magisk and so on is because it's spoofing an older device (launched before Android 8) without hardware-bound keys and Google is deliberately allowing that in order not to blacklist the genuine users.
However, once Google decides that the collateral damage is tolerable and those devices should no longer pass Play Integrity, then it's game over. You can't spoof any newer stuff, as you can't produce the desired signature -- only the hardware can do it and the hardware won't do it.
The only way would be if the manufacturer screwed up and it's possible to run unsigned code (or signed by a different key) and maintain a pristine bootloader, or if the hardware key leaks somehow. In either case, the key is per device so Google is always free to blacklist that device if it really wants to. (Verification of the signatures is always done off-device, through Google's servers.)
Re: What happened to running what you wanted on your own machine?
#284Earlier quoted context omitted.
Let me try to strawman a little: I personally accept this on my phone because I honestly don't consider my phone to be a computer, and I don't really care about "computing" on it. My phone is not really that important to me. It is a toy/appliance that I goof around with. What it's running and how "free" and "open" it is, is about as important to me as how free the firmware in my car is, or the software on my gaming c…
You have nothing to fear, if you have nothing to hide. Right?
Re: What happened to running what you wanted on your own machine?
#285Earlier quoted context omitted.
In my country, the same verification service is used to access banks, health services (private and public), taxes, and even verify online retail purchases. This verification app on Android requires Play Integrity on first time activation so fresh installs of something like GrapheneOS will not let you use the app. It's still currently possible to use a hardware token alternative to the app. It is only getting less con…
I see all of these "in my country, we need a phone to do X" posts, and while I believe them, I feel like they always leave out key information. I'd also like to know: What actually happens when the customer does not have a phone? Do you just never get healthcare? Do you just never bank? Surely there are (perhaps inconvenient) alternatives that people without phones can use. The national government doesn't just let it…
For government services, both will work. But you must use some of them, otherwise no government for you. You can still do some things by paper, but those are getting rarer and rarer nowadays. The general assumption is that everything is done online. Some government services can't be done by paper or physical visit, not without involving this authentication at some point.
For most of everything else, only BankID (the oldest of the two and the most deployed by far). Especially for banking, only this works. Even if you call the bank and try to sort out via phone, they will refuse service until you can prove that you are you by authenticating via BankID.
But Sweden is mostly cashless nowadays (even some bank branches are refusing to deal with cash). For example, you can't take a bus or train and pay with cash. You have to use a vending machine that only exists on train stations, or depending on which kind of transport and the region you live you might be able to do a contactless payment, or you must use the app (the default choice that 99% use). If you use the app, to pay you need to use a "card not present" flow, or Swish (Sweden's mobile payment system), and to complete either you must use BankID. You can't use your card or do any payment without BankID (if the card is not present).
Even if you do use your card, if it gets denied for any reason, for you to sort out the issue you'll need the mobile phone and BankID.
If you go out with friends to a restaurant, most restaurants don't accept cash. If the restaurant doesn't accept charging each one individually then someone needs to pay for the group, and they will expect you to pay them via Swish which requires BankID. People won't take cash either.
As you can see, it's not actually trivial here to live as part of society without a working mobile phone. If you're outside, you better have 100% faith on your card, and/or be prepared that you might need to walk back home as you can't do much now, might not even be able to buy transportation.
Some smaller shops/kiosks only take Swish: no cash, no card. That requires a phone plus BankID.
If (or better said: when) BankID starts requiring the device to pass Play Integrity, then not only you must be carrying the device at all times, but it must be a blessed device from Google or Apple.
In Denmark the situation is very similar, and in their case their app (which is called MitID) already mandates that the device has to pass Play Integrity.
Re: What happened to running what you wanted on your own machine?
#286Earlier quoted context omitted.
> Many banks now also use their app as a second factor, rather than a generic OTP option that can run on any hardware. This is one I’m willing to tolerate, as long as it’s optional. Something I don’t understand though is banking app setup. When I got a new phone this year, the RBC app made me submit some kind of live selfie. The thing is, I know they can scan your debit card with NFC and authenticate the PIN. I’ve us…
do you not use the banks ATM or go into a branch ever? why would they not have anything to compare it to?
It would be quite a scandal, legally and socially, if it was discovered that a bank was creating a database of images of their customers without consent.
Re: What happened to running what you wanted on your own machine?
#287> Vote with your wallet Doesn't work when the only options are bad. Every Android OEM embraces the closing of android because it'll allow them to ship all the spyware they already do without the user being able to remove them (or disable them soon enough). Having 2 or 100 options has no difference if they're all bad.
How will Google know about my choice? I want to let them know that now there is no reason anymore to prefer to Android over another ecosystem. Also, my hardware, my choice. It seems there is no way to actually let them know.
1) sign a petition on change.org against that APK lockdown (currently 10.5k votes) - https://c.org/BHZzNvR6pr
2) In your Android device or Google account use "Send Feedback" and articulate yourself or "Contact us" in Android under "System settings > Tips and support" or best, if you are paying subscriber for any Google LLC service, send the feedback through the subscription management channels (such as feedback in Google One, Workspace or any other paid service)
Re: What happened to running what you wanted on your own machine?
#288Earlier quoted context omitted.
I see all of these "in my country, we need a phone to do X" posts, and while I believe them, I feel like they always leave out key information. I'd also like to know: What actually happens when the customer does not have a phone? Do you just never get healthcare? Do you just never bank? Surely there are (perhaps inconvenient) alternatives that people without phones can use. The national government doesn't just let it…
So what actually happens in Sweden: there are two officially sanctioned authentication apps: BankID (originally developed by banks) and Freja. Both only run on a mobile phone. For government services, both will work. But you must use some of them, otherwise no government for you. You can still do some things by paper, but those are getting rarer and rarer nowadays. The general assumption is that everything is done on…
Re: What happened to running what you wanted on your own machine?
#289Earlier quoted context omitted.
How will Google know about my choice? I want to let them know that now there is no reason anymore to prefer to Android over another ecosystem. Also, my hardware, my choice. It seems there is no way to actually let them know.
I'd go with 1) sign a petition on change.org against that APK lockdown (currently 10.5k votes) - https://c.org/BHZzNvR6pr 2) In your Android device or Google account use "Send Feedback" and articulate yourself or "Contact us" in Android under "System settings > Tips and support" or best, if you are paying subscriber for any Google LLC service, send the feedback through the subscription management channels (such as fe…
Re: What happened to running what you wanted on your own machine?
#290Earlier quoted context omitted.
do you not use the banks ATM or go into a branch ever? why would they not have anything to compare it to?
Canada has strong privacy protections and norms. It would be quite a scandal, legally and socially, if it was discovered that a bank was creating a database of images of their customers without consent.
According to ChatGPT: Only Illinois, Texas, and Washington really constrain that, and Illinois is the only one with real teeth.