Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

531–540 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#531

Earlier quoted context omitted.

> it would be better if they removed the claim “It doesn't provide a useful security feature” because, even if it does, What evidence is there that it does? Attestation purports to prove the code is running on an "approved" device. There are multiple reasons that has no real security value. The first is that "approved" not only has no relationship to "secure", they're actually anti-correlated . As the article points…

> Attestation purports to prove the code is running on an "approved" device. There are multiple reasons that has no real security value. BART (San Francisco Bay Area Rapid Transit), as a real world example, recently installed "evasion-proof" fare gates, and observed a 90% drop in vandalism-related maintenance expense. An overwhelming majority of fare evaders are not vandals, but apparently nearly all vandals were far…

> In other words, banks and governments and other such institutions have noticed (and they probably do have data to back this up) that very few of their customers use "unapproved" devices and a very large majority of fraud comes from "unapproved" devices.

What would cause you to think that to be the case?

There are two primary ways that bank fraud happens. The first is that the attacker steals the user's credentials, at which point they can sign into the user's account and transfer funds, and can use any device the bank requires because they already have the credentials. The second is that the attacker convinces the user to transfer the money and then once again the user is using an approved device if that is required, and requiring it in no way prevents the attack.

Moreover, even if there was a statistical correlation -- which there is no reason to expect in this case -- that doesn't help you when the attackers could just use their stolen credentials on an approved device anyway, regardless of what they were doing before.

Vandalism can be reduced by excluding fare evaders because that's a class of people rather than a class of devices. Requiring the attackers to use an approved device when the approved device still allows them to commit the fraud accomplishes nothing.

Re: Hardware Attestation as Monopoly Enabler

#532
post #6

Our civilization desperately needs a method to modify modern microelectronics after manufacturing that can be used at least in a well-equipped repair shop, and it needs it yesterday. Alternatively, just make it illegal to ship any kind of initial bootloader as part of a CPU's/SoC's mask ROM in any computing device that is marketed as a general-purpose one. I.e. the first instruction that the CPU executes after reset…

> Alternatively, just make it illegal to ship any kind of initial bootloader as part of a CPU's/SoC's mask ROM in any computing device that is marketed as a general-purpose one.

Funny, I have a related proposal: make it illegal to sell hardware and distribute software. Or at least, if you distribute software, we don’t buy your hardware. The idea is to force hardware companies to release the complete user manual for their hardware, and incentivise them to simplify and standardise their hardware interfaces.

What I did forget was forbidding them to arbitrarily restrict what kind of software can run with their hardware, which they could if the hardware hashes the software & verifies a signature before running it. But it would seem your separation between CPU and storage takes care of that.

Re: Hardware Attestation as Monopoly Enabler

#533

Earlier quoted context omitted.

Requiring "tokens" stored in "trusted modules" and 7-factor-auth for everything is not progress, it's theater. The biggest achievement of the security orthodoxy was locking me out of my email, by requiring me to read a code sent to my email to log into my email. I -- literally -- do not care about a single "account" in any "service" I use aside from my email and bank account. Most people would add a few social media…

What about Apple Wallet? The reality is that there is software dependent on the user being unable to modify it. This safeguards the server against fraudulent users.

Never trust user input. The users already can't modify the server.

And what actual applications did you have in mind that warrant throwing everybody under the bus? (by that I mean some applications (allegedly) need it, so it gets forced on everyone)

Re: Hardware Attestation as Monopoly Enabler

#534

Requiring authorized silicon (and software) isn't even the biggest problem here. They do not use zero knowledge proof systems or blind signatures. So every time you use your device to attest you leave behind something (the attestation packet) that can be used to link the action to your device. They put on a show about how much they care about your privacy by introducing indirection into the process (static device 'ID…

Can you revoke certificate for a specific device using privacy schemes? Like imagine that someone managed to extract key from the specific device and distributed that key in a software implementation to fake attestation. Now Google needs to revoke that particular key to disallow its usage. This is obvious requirement.

Especially if the device in question is linked to an enemy of the state and the people.

Re: Hardware Attestation as Monopoly Enabler

#535
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged.

Apple already does this and practically no one is outraged

Re: Hardware Attestation as Monopoly Enabler

#536
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

[deleted]

Re: Hardware Attestation as Monopoly Enabler

#537
post #310

Earlier quoted context omitted.

>RMS found it acceptable to use SunOS initially to create GNU. Any source on that?

I know it from personal experience using GNU tools on Sun early on (really Solaris in my case, I wasn't quite that early a user), and I think from a talk or essay by RMS but for a moment I worried it might have been personal correspondence. Finding a citation seemed like a fun challenge: https://www.gnu.org/gnu/thegnuproject.html > [...] the easiest way to develop components of GNU was to do it on a Unix system, and…

Thanks for the quote, I couldn't find anything online.

Although it seems to me that the comparison is somewhat fragile : it was not possible to develop GNU anywhere else, whereas we could completely build local models from scratch nowadays, unless I'm mistaken.

Re: Hardware Attestation as Monopoly Enabler

#538

Earlier quoted context omitted.

>We have over 30 years of the world wide web and for these more than 3 decades this was never a problem. Are you seriously trying to suggest copyright infringement has not been an issue over the last 30 years? Both of them are solutions to problems that we've had over the last 30 years and were created for the greater good to solve problems that developers were facing.

Tell me when DMCA law has worked in favor of small companies/developers? DMCA is abused every. single. time.

Individual self employed photographers successfully use the DMCA to get significant payouts from large publishers and news organisations every single day.

Like literally hundreds of thousands, every day.

Re: Hardware Attestation as Monopoly Enabler

#539
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged

Because Apple always did this, everybody knew this and people buy Apple exactly because of this.

Google now pulls the rug on Android which is a whole different story because it used to be open. The whole idea of Android was to be open.

Re: Hardware Attestation as Monopoly Enabler

#540

Earlier quoted context omitted.

> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged

Because Apple always did this, everybody knew this and people buy Apple exactly because of this. Google now pulls the rug on Android which is a whole different story because it used to be open. The whole idea of Android was to be open.

The biggest mistake is that people trusted a company that, in reality, isn't that different from Apple. Just because everyone claimed Android as the true open source alternative to iOS, when only AOSP was that.
Post reply on HN