Earlier quoted context omitted.
> it would be better if they removed the claim “It doesn't provide a useful security feature” because, even if it does, What evidence is there that it does? Attestation purports to prove the code is running on an "approved" device. There are multiple reasons that has no real security value. The first is that "approved" not only has no relationship to "secure", they're actually anti-correlated . As the article points…
> Attestation purports to prove the code is running on an "approved" device. There are multiple reasons that has no real security value. BART (San Francisco Bay Area Rapid Transit), as a real world example, recently installed "evasion-proof" fare gates, and observed a 90% drop in vandalism-related maintenance expense. An overwhelming majority of fare evaders are not vandals, but apparently nearly all vandals were far…
What would cause you to think that to be the case?
There are two primary ways that bank fraud happens. The first is that the attacker steals the user's credentials, at which point they can sign into the user's account and transfer funds, and can use any device the bank requires because they already have the credentials. The second is that the attacker convinces the user to transfer the money and then once again the user is using an approved device if that is required, and requiring it in no way prevents the attack.
Moreover, even if there was a statistical correlation -- which there is no reason to expect in this case -- that doesn't help you when the attackers could just use their stolen credentials on an approved device anyway, regardless of what they were doing before.
Vandalism can be reduced by excluding fare evaders because that's a class of people rather than a class of devices. Requiring the attackers to use an approved device when the approved device still allows them to commit the fraud accomplishes nothing.