Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

461–470 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#461
post #427

Earlier quoted context omitted.

I have 2 servers, Alice and Bob, Bob has a secret, I want Bob to be able to share that secret with Alice. However, I want Alice to be able to prove to Bob that it is actually Alice, that it is running the correct AliceOS, and that AliceOS was loaded on bare metal Alice without nefarious pre-book or virtualization hooks. A TPM with measured boot (SecureBoot) does exactly this, remote attestation is how Alice proves to…

As someone who wanted to improve users security, that’s exactly why I find this thread fanatical opposition to attestation baffling. Nearly everyone uses a device that supports hardware attestation. It’s the best available tool to protect users from malware. We do implement a fallback that lowers security but lets the few users who have devices not able to attest properly to continue, but that really lowers security…

Sadly, the problem isn't the TPM or Remote Attestation. It's Google et al choosing to only talk to devices and software they like without concern for what the user wants or trusts. Compounded by everyone else just going along with it.

A TPM where the device owner can't take ownership of the root key is worse then no TPM at all.

Re: Hardware Attestation as Monopoly Enabler

#462

Earlier quoted context omitted.

The problem with the reasonable framing you suggest is that it gets thrown out of the window the moment someone utters Protect the Children®. I'm willing to bet that most people, including those with kids like myself, don't truly believe that surrendering our basic rights to better protect the children is a rational thing to do, but they would never dare to push their opinion publicly. The few that do get all but lab…

I don't actually believe this. People don't actually believe every car should have a GPS tracker so that if a pedophile drives a car, the police can track it. That is a ridiculous argument, and if they make it, there should be something you can say to make it blow up in their face. Unfortunately, as we've all now discovered, winning arguments isn't about being right, so I don't know which words you can say to make th…

"Criminals will adapt and avoid while the public gets transparent." Is my simple response.

Re: Hardware Attestation as Monopoly Enabler

#463

Earlier quoted context omitted.

The problem with the reasonable framing you suggest is that it gets thrown out of the window the moment someone utters Protect the Children®. I'm willing to bet that most people, including those with kids like myself, don't truly believe that surrendering our basic rights to better protect the children is a rational thing to do, but they would never dare to push their opinion publicly. The few that do get all but lab…

I don't actually believe this. People don't actually believe every car should have a GPS tracker so that if a pedophile drives a car, the police can track it. That is a ridiculous argument, and if they make it, there should be something you can say to make it blow up in their face. Unfortunately, as we've all now discovered, winning arguments isn't about being right, so I don't know which words you can say to make th…

People already showed that they will swallow anything as long as it's attached to "protect from the terrorists" label. Protect the children is an even more powerful extension. Few people ever really have to worry about terrorists but kids, that's a different story.

My logical assumption is that all terrorists and pedophiles will concentrate in the areas where they have legal exceptions from being monitored by multiple different parties at any given time. Legislators and the like. To play one of their cards, why would people who love to say "innocent people have nothing to hide" have something to hide?

Re: Hardware Attestation as Monopoly Enabler

#464
post #447

I always say this when this topic comes up: remote attestation will be how our computing freedom dies. They've made it so that it doesn't even matter if they allow you to install whatever you want. Anything that isn't corporate owned is banned. Own your device? You "tampered" with it. You're banned. From everything. You're ostracized from digital society. You're not even a citizen, much less a second class citizen. E…

For once, we may be "saved" thanks to Trump. Because of the brutal change in geopolitics he triggered, the EU is now actively looking at all the hard dependencies on US controlled systems. Android and iOS are two of them. I cannot tell if the alternative solution will be better, but I do think we will develop alternatives.

Are they really tho? The EU is currently enforcing a digital ID that will depend on Android and iOS in most implementations

Re: Hardware Attestation as Monopoly Enabler

#465
post #447

Earlier quoted context omitted.

For once, we may be "saved" thanks to Trump. Because of the brutal change in geopolitics he triggered, the EU is now actively looking at all the hard dependencies on US controlled systems. Android and iOS are two of them. I cannot tell if the alternative solution will be better, but I do think we will develop alternatives.

Are they really tho? The EU is currently enforcing a digital ID that will depend on Android and iOS in most implementations

Not only that, they're also enforcing age verification, i.e. mass surveillance.

Re: Hardware Attestation as Monopoly Enabler

#466

I always say this when this topic comes up: remote attestation will be how our computing freedom dies. They've made it so that it doesn't even matter if they allow you to install whatever you want. Anything that isn't corporate owned is banned. Own your device? You "tampered" with it. You're banned. From everything. You're ostracized from digital society. You're not even a citizen, much less a second class citizen. E…

> You're ostracized from digital society. You're not even a citizen, much less a second class citizen.

Before anyone downplays this concern as scaremongering ans slippery slope fallacy stuff, keep in mind that countries are shifting their national ID cars infrastructure to online services which are fundamentally designed around attestation. Moreover some class of services such as banking are progressively increasing requirements that your software and hardware needs to meet to allow you to manage your own property.

Re: Hardware Attestation as Monopoly Enabler

#467

Ironically, the other top article on HN right now is CVE-2024-YIKES. You can't have the cake and eat it too. Maybe we need to close some doors, especially if the barrier for publication is literally just a couple of prompts and uploading the result to distributor like npm or play store.

A Big Brother dictating what is allowed isn't necessary for your security. Virtualization can be the solution. See: https://qubes-os.org

Re: Hardware Attestation as Monopoly Enabler

#468
post #364

Earlier quoted context omitted.

Weird rant. TPMs are great. The modern computing landscape needs a safe place to put secrets. It's what made the iPhone (Secure Enclave is effectively a TPM) years ahead of Android in terms of security. The problem isn't the TPM, but attestation. As soon as the TPM is required to not be under your control to get access to Y, bad things happen. Hell, in actuality, the problem isn't even attestation, its policy. The EU…

Requiring "tokens" stored in "trusted modules" and 7-factor-auth for everything is not progress, it's theater. The biggest achievement of the security orthodoxy was locking me out of my email, by requiring me to read a code sent to my email to log into my email. I -- literally -- do not care about a single "account" in any "service" I use aside from my email and bank account. Most people would add a few social media…

Passkeys are better passwords. They need a TPM.

Re: Hardware Attestation as Monopoly Enabler

#469

Earlier quoted context omitted.

Maybe not all of them, but certainly a few large, popular ones. You bring up a good point though, it seems surprising that Wero/PEPSI don't have more momentum. Maybe Europeans hate their continental neighbors more than American financial conglomerates.

We just don't know much about one another. I never really thought about it until I saw this comment: https://news.ycombinator.com/item?id=45993140

Unfortunately, each European country has a different "national" payment method.

Swish in Sweden, MobilePay in Denmark/Finland, iDEAL in the Netherlands, etc. Of course you can't sign up to a specific country payment system if you're not a resident there. And systems from different countries don't work with each other.

Luckily, there's now an initiative called EPI [1], which is an alliance that wants to make all these apps interoperable and call them "Wero" [2].

There are two problem with this system though:

- Wero insists on making you use your own bank app to send/receive payments. That's a terrible choice, because most bank apps are huge behemoths that are slow and heavy. People don't want to use them: PayPal is so much quicker and easier. They should develop a new, lightweight app that only does payments.

- The Italian member of EPI is "BancomatPay", which nobody uses. Sure, Bancomat is a huge company in the debit cards world, but no sane person uses BancomatPay in their daily life (also, BancomatPay forces you to use your bank app). In Italy, Satispay is way bigger and widely accepted, especially in the North (i.e. richest) part of the country. I'm surprised Satispay didn't get into EPI.

[1] https://epicompany.eu/ [2] https://wero-wallet.eu

Re: Hardware Attestation as Monopoly Enabler

#470

Earlier quoted context omitted.

While I agree, I think there's a better way to frame this with the public. We don't need to bring in pedo references. That looks very unhinged to most people. There's already a lot of support out there, in both public opinion and the law, for the idea that if I pay for something physical like a device, I own it. Any substantial alteration in its functionality, especially a reduction in what it can do, requires my con…

The problem with the reasonable framing you suggest is that it gets thrown out of the window the moment someone utters Protect the Children®. I'm willing to bet that most people, including those with kids like myself, don't truly believe that surrendering our basic rights to better protect the children is a rational thing to do, but they would never dare to push their opinion publicly. The few that do get all but lab…

There's an answer for that now: "Release ALL the Epstein files."
Post reply on HN