Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

561–570 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#561
post #553

Earlier quoted context omitted.

> Because Apple always did this, everybody knew this and people buy Apple exactly because of this. Is that really so? Does the average iPhone user actually factor the app store tax into their decision to purchase the device? Or do they just assume that is just how all software works because they have no exposure to software ecosystems outside the iPhone app store

They factor in a more "clean" appstore yes. Not the tax itself but they usually appreciate apple having more polished apps in general (given that the Google Playstore is full of trash).

Google play store is only full of trash if you go hunting for trash. I'd like to see the actual stats of people affected by play store malware vs malware available on the play store.

I'm not saying it's not a problem, but I am saying it's not a problem that has caused any problems with any Android user I've ever met.

Re: Hardware Attestation as Monopoly Enabler

#563

Earlier quoted context omitted.

Can you show me examples where locking down an OS has prevented fraud in banking? Honestly, if the only way to secure your banking system is by locking down users' devices, there is something really bad going on at your end, security-wise. Your system should be secure even without locking down user hardware.

One of the threat models is that a fraudster tricks a non-technical user into installing malware, which then manipulates the user interface so that next time the user tries to send money to Bob, it actually goes to Mallory. That's a legitimate concern, and one of the causes why PSD2 mandates that all 2FA devices must have a display that shows the user where they're about to send the money and how much.

And one of the threat models that police use in the US is tracking women suspected of going for abortions through the use of road cameras, and other surveillance methods.

Once you have the attestation in place you have no guarantee who is going to get access to data like what apps are present on your device, and there will be nothing you can do to stop it.

Meanwhile, we could educate people against common scams.

How is this not just trading one smaller bad for a bigger bad? Why is this touted as an improvement?

Re: Hardware Attestation as Monopoly Enabler

#564
post #554

Earlier quoted context omitted.

I have been using Apple devices for almost 20 years, and I have never been forced to pay a 30% tax on all activity on my phone. I can avoid it by buying directly from the seller's website, and also I just avoid buying software subscriptions in general, but especially from the App Store. 99% of the payment activity I do on my phone (buying retail goods, travel arrangements, paying invoices) has no additional cost.

No? Apple charges a fee on every app sale. Where do you think the app makers pay that walled garden tax?

Never spent money on an app on my phone.

Re: Hardware Attestation as Monopoly Enabler

#565
post #431

Earlier quoted context omitted.

Do you think banks are using attestation gratuitously? It helps prevent a lot of fraud. You are opposing something that saves people’s savings every day just because you think it takes “freedom” away from a few hobbyists. Do you even have a phone that does not support hardware attestation or is all this posturing about something hypothetical?

Can you show me examples where locking down an OS has prevented fraud in banking? Honestly, if the only way to secure your banking system is by locking down users' devices, there is something really bad going on at your end, security-wise. Your system should be secure even without locking down user hardware.

> Can you show me examples where locking down an OS has prevented fraud in banking?

This is a non-sensical remark because it's impossible to "prove" a counterfactual. I find stuff like this incredibly annoying - please don't say this.

Re: Hardware Attestation as Monopoly Enabler

#566
post #553

Earlier quoted context omitted.

Because Apple always did this, everybody knew this and people buy Apple exactly because of this. Google now pulls the rug on Android which is a whole different story because it used to be open. The whole idea of Android was to be open.

> Because Apple always did this, everybody knew this and people buy Apple exactly because of this. Is that really so? Does the average iPhone user actually factor the app store tax into their decision to purchase the device? Or do they just assume that is just how all software works because they have no exposure to software ecosystems outside the iPhone app store

> Does the average iPhone user actually factor the app store tax into their decision to purchase the device?

As I'm the IT tech support for some family members, I certainly do. A lot less drama and garbage when using Apple products (generally speaking).

I've sysadmined Linux for a living for many moons now, and used to run Linux and then FreeBSD at home, and I switched to Apple for personal stuff during the PowerPC and early Mac OS 10.x timeframe because I did enough fiddling with tech at work and minimized it at home.

I used Linux desktops at work in the pre-COVID era when we still had offices and such. I now use a Apple laptop as I can get Unix-y tools to admin: I spend >80% of my time in Terminal (the rest in Safari and Mail).

Re: Hardware Attestation as Monopoly Enabler

#567

Earlier quoted context omitted.

They factor in a more "clean" appstore yes. Not the tax itself but they usually appreciate apple having more polished apps in general (given that the Google Playstore is full of trash).

Google play store is only full of trash if you go hunting for trash. I'd like to see the actual stats of people affected by play store malware vs malware available on the play store. I'm not saying it's not a problem, but I am saying it's not a problem that has caused any problems with any Android user I've ever met.

I am not talking about the malware, I am talking about the apps that are bloated with advertisements or try really hard to push a subscription upon you. Lots of "free" apps try to push you into a subscription once installed.

Re: Hardware Attestation as Monopoly Enabler

#568

Earlier quoted context omitted.

Look at the last 30 years of computing history? When online banking was first created it was an absolute chaos zone. Everyone was accessing it from desktop machines riddled with viruses and malware. There are endless stories of being discovering their life savings had been wired to Belarus by some malware running on their machine that had grabbed their banking credentials when they logged in. https://www.google.com/s…

> Secondly, it's a lot more convenient to use a device that's always with you than a dedicated standalone single-use computer. The price the owner pays for this is that they're locked out of their own expensive general-purpose computing device while still having to bear all the inconveniences (babysit OS updates, configure stuff, keep it charged, have the battery fail, buy a new device every five years, etc.) In the…

This reminds me of crypto wallets. I also dispute mike_hearn 's:

> Smartphone HW attestation is better in every way

They're still prone to side-channel attacks like SPECTRE. Crypto wallets are practically immune because they're air-gapped.

[edit] I just realised that's Mike Hearn of early BTC fame. I suppose he would know what a crypto wallet is.

Re: Hardware Attestation as Monopoly Enabler

#569
post #560

It's the 3rd or 4th of threads like this in the front page and it's still not clear to me what are the alternatives that privacy advocates vouch for? Dead internet theory is happening, you have botnets with more budget than most of the third world countries and you could also add openclaw usage to same bucket. There's a real need for a protocol or specification for how to attest that an action was really done by a hu…

> Dead internet theory is happening, you have botnets with more budget than most of the third world countries and you could also add openclaw usage to same bucket.

So what's the actual issue here? That on HN and Reddit and Instagram and X there'll be a lot of bots? As if they haven't been overrun by human astroturfers/etc for ages. Even ignoring that, what's the biggest issue you see with that, and why is it so big that it's fine to just enable a monopoly?

Your presumption that there has to be an alternative is flawed. Maybe there is none. You're saying there's a real need, great. There's also a real need for sexual assault to be completely eliminated worldwide. I think everyone would agree with the that need is far bigger than bots on social networks. Doesn't mean we should just jail everyone just in case.

You're manufacturing a need here as so important that by definition the ends justify the means. They don't.

Post reply on HN