Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

431–440 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#431
post #245

Earlier quoted context omitted.

The biggest problem is banking system. "Don't want - no bank for you". That's the problem.

Let them know. Write a letter to the CEO. And vote with your wallet and switch banks if you can. There's always a bank willing to offer you a non-app 2FA scheme.

Do you think banks are using attestation gratuitously? It helps prevent a lot of fraud. You are opposing something that saves people’s savings every day just because you think it takes “freedom” away from a few hobbyists. Do you even have a phone that does not support hardware attestation or is all this posturing about something hypothetical?

Re: Hardware Attestation as Monopoly Enabler

#432

I always say this when this topic comes up: remote attestation will be how our computing freedom dies. They've made it so that it doesn't even matter if they allow you to install whatever you want. Anything that isn't corporate owned is banned. Own your device? You "tampered" with it. You're banned. From everything. You're ostracized from digital society. You're not even a citizen, much less a second class citizen. E…

While I agree, I think there's a better way to frame this with the public. We don't need to bring in pedo references. That looks very unhinged to most people.

There's already a lot of support out there, in both public opinion and the law, for the idea that if I pay for something physical like a device, I own it. Any substantial alteration in its functionality, especially a reduction in what it can do, requires my consent. Reduction in what it can do should require my consent. Just because tech made it possible for the manufacturer to brick my phone or my car, start charging me extra for certain features I already paid for, or block the apps the OS vendor doesn't approve of doesn't mean they should or that it's even legal to do so. Additionally once I buy the device the vendor has zero business telling me how I can modify it, or whether I can repair it.

I own the thing I bought, fucker. It's my property and I have property rights. The corp has no right to steal away part of the thing I bought or change the terms after the fact. It's potentially criminal if they try.

This framing resonates with a lot of people.

The guy who really exemplifies this positioning at the moment is Louis Rossman and by focusing on these widely understood and popular concepts, he's gained the ability to direct an enormous amount of attention to an issue. He can absolutely swamp a legislature with letters from angry constituents for example when he gives an issue visibility.

Frame it as theft because it is. If they push an update without my consent that removes functionality or sabotages my ownership of the device, it's theft. At the very least product liability laws should apply. Some part of what I bought stops working, that goes to product liability. But I'd take it a step farther and say we're dealing with straight up theft.

Re: Hardware Attestation as Monopoly Enabler

#433

Earlier quoted context omitted.

Keep fighting. Spread the word. Ensure that everyone you know is aware of the totalitarian implications. The only way to sure defeat is to surrender.

I will, but it doesn't look good.

Then we should step it up a bit.

Re: Hardware Attestation as Monopoly Enabler

#434

Earlier quoted context omitted.

Are there enough of us to run our own country? It makes me feel dumb, but this is a serious question.

If you live in a democracy, you already do run your own country. Vote accordingly. Get involved in politics.

The problem is democracy and capitalism are incompatible, so that "if" is doing some really heavy lifting.

Re: Hardware Attestation as Monopoly Enabler

#435
post #245

Earlier quoted context omitted.

The biggest problem is banking system. "Don't want - no bank for you". That's the problem.

Let them know. Write a letter to the CEO. And vote with your wallet and switch banks if you can. There's always a bank willing to offer you a non-app 2FA scheme.

Banks don’t do this because of profit. They do it because of decades of laws pushing in this direction. Anti-money laundering, know your customer, digitalised currency, abandoning cash, preventing tax evasion etc… it’s been getting more extensive over time.

Re: Hardware Attestation as Monopoly Enabler

#436

Earlier quoted context omitted.

Do you consider being banned in a video game because of hacking to be an example of something killing computing freedom? The user still maintains all the freedom of doing whatever computing they want on their own machine, but if they want to play with others who don't want to play with cheaters then they have to use the official client. For people who want a high degree of freedom and be able to access as many digita…

How about being banned from online banking, government services and all social networking / communication platforms? Because that's the road we're already heading down. What makes you think they will give us this magical hypervisor capability? It's more effort, increases the chances someone finds a bypass and takes power away from the incumbent online platforms. It's so much easier to just prevent it all. The only re…

>How about being banned from online banking, government services and all social networking / communication platforms?

You aren't banned. You just have to use a secure device. It's like saying that a store banned you because they stopped taking checks and started requiring a credit card since they are more secure and harder to commit fraud with. As a person you didn't lose any freedom. Freedom does not mean someone has to be able to force their will on another person. That sounds like the opposite of freedom to me.

>What makes you think they will give us this magical hypervisor capability?

It's not magical. Look at Windows WSL2 which already works like that.

Re: Hardware Attestation as Monopoly Enabler

#437

Earlier quoted context omitted.

If you’re not, and I say this in good faith, take your own advice around your tone. Making assumptions about other people, and then doubling down when they correct you, comes across as a kind of horrible I doubt you truly are.

I say this in good faith: oh, stop.

does it piss you off that punct isn't used properly anymore and that, commas, can happen anywhere? Are you one of those who still has use for em-dash?

Re: Hardware Attestation as Monopoly Enabler

#438
I agree with Graphene's take here.

I've defended app attestation against baseless criticism, but this is a valid take.

The only nuance I would make is that hardware attestation as a technology isn't inherently anti-competitive but rather the way these companies implement it.

I would love to see a non-profit attestation service that publishes a list of allowed OS's, and roots that are deemed secure based on reality.

Re: Hardware Attestation as Monopoly Enabler

#439

Earlier quoted context omitted.

Do you consider being banned in a video game because of hacking to be an example of something killing computing freedom? The user still maintains all the freedom of doing whatever computing they want on their own machine, but if they want to play with others who don't want to play with cheaters then they have to use the official client. For people who want a high degree of freedom and be able to access as many digita…

I think you got it reverse. Gaming and such are dedicated services. Fine if people agree to pay premium to have the required platform / console / etc. General services such as communications / banking must be free, and must not require trusted hardware on the end point. The services must be designed to be secure even in the case of compromised end points. But that's against the current trend where all banks are tryin…

>How about being banned from online banking, government services and all social networking / communication platforms?

Defense is depth actually works. It's better security to require a dedicated device to make it harder to commit fraud. This is why credit cards became a secure device instead of just being a magnetic strip.

Re: Hardware Attestation as Monopoly Enabler

#440

Earlier quoted context omitted.

How about being banned from online banking, government services and all social networking / communication platforms? Because that's the road we're already heading down. What makes you think they will give us this magical hypervisor capability? It's more effort, increases the chances someone finds a bypass and takes power away from the incumbent online platforms. It's so much easier to just prevent it all. The only re…

>How about being banned from online banking, government services and all social networking / communication platforms? You aren't banned. You just have to use a secure device. It's like saying that a store banned you because they stopped taking checks and started requiring a credit card since they are more secure and harder to commit fraud with. As a person you didn't lose any freedom. Freedom does not mean someone ha…

It's not about being secure. Google allows devices with up to 10 years without any patches to pass their integrity API. Meanwhile Graphene OS, which is very secure and up-to-date, doesn't pass.
Post reply on HN