Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

571–580 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#571

Earlier quoted context omitted.

I have been using Apple devices for almost 20 years, and I have never been forced to pay a 30% tax on all activity on my phone. I can avoid it by buying directly from the seller's website, and also I just avoid buying software subscriptions in general, but especially from the App Store. 99% of the payment activity I do on my phone (buying retail goods, travel arrangements, paying invoices) has no additional cost.

You're correct. You've just paid it on every app store purchase, and every in app purchase. That's because Apple, despite trying, have failed to completely lock in the payment infrastructure. They really want to though. Maybe consider that.

I consider almost everyone really wants to earn more money, more easily.

I do not see any indication that Apple wants to get involved in adjudicating payment disputes for physical goods and services. That is high cost, high liability, low margin work. They seem to be perfectly happy letting the existing banks (aka card issuers) handle that, and getting a 0.15% cut for allowing their credit cards to use Apple Pay.

Apple has restricted themselves to being the payment infrastructure for only digital goods, and I assume that is because that is the cheaper, more scalable option.

As a side note, in the US, the proportion of sellers willing to eat the credit card fees has gone down every year, and seemingly at an accelerating pace. I have winnowed down my credit card usage to retail goods/restaurants/travel, because almost everyone else wants payment via ACH/Debit/Zelle/other option that avoids credit card fees, so I would be surprised if Apple would ever want to enter this market, given that even the 2% credit card fee transactions are not able to compete.

Re: Hardware Attestation as Monopoly Enabler

#572

Earlier quoted context omitted.

The problem with the reasonable framing you suggest is that it gets thrown out of the window the moment someone utters Protect the Children®. I'm willing to bet that most people, including those with kids like myself, don't truly believe that surrendering our basic rights to better protect the children is a rational thing to do, but they would never dare to push their opinion publicly. The few that do get all but lab…

I have decided that if they'll play dirty then I will. If someone says "protect the children" then I smear those saying it, e.g. Kier Starmer wants to protect children? He put Mandelson into government even though he was mates with Epstein. Doesn't sound like someone who cares about protecting children to me. Rinse and repeat for any politician or political side, they are all only a step or two away from someone who'…

> Rinse and repeat for any politician or political side, they are all only a step or two away from someone who's done something horrible to children.

Not true, some aren't. Namely the tiny minority who pushes against this sort of stuff.

Re: Hardware Attestation as Monopoly Enabler

#573

Requiring authorized silicon (and software) isn't even the biggest problem here. They do not use zero knowledge proof systems or blind signatures. So every time you use your device to attest you leave behind something (the attestation packet) that can be used to link the action to your device. They put on a show about how much they care about your privacy by introducing indirection into the process (static device 'ID…

> The other is that because it's not possible to link an attestation to a particular device the only mitigation to abuse that is feasible is rate limiting I still don't see how you can keep something anonymous and still rate limit it. If a service can tell that two requests came from the same party in order to count them then two services can tell that two requests came from the same party (by both pretending to be t…

[deleted]

Re: Hardware Attestation as Monopoly Enabler

#574
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged

Frame it as "America will decide what you can do with your phone" and people in Europe will listen.

Re: Hardware Attestation as Monopoly Enabler

#575
post #395

Earlier quoted context omitted.

No, it's not. The biggest foreign actors driving far right nationalism are people like Rupert Murdoch, Andrew Tate and going forwards potentially Jeff Bezos. Murdoch has been the single biggest driver for decades. If they would truly be interested in stopping foreign propaganda they'd go after them instead. It's especially ironic to name China when the whole reason the US bought TikTok is because it showed people the…

You might not be from Europe then. Russia is the primary threat. They are funding extremist political movements. They are also conducting sabotage and espionage operations inside the EU.

> They are funding extremist political movements. They are also conducting sabotage and espionage operations inside the EU.

These are true. They also don't have much to do with what I replied to, which was about "the propaganda efforts driving a large amount of far right nationalists into violent uprising."

You're simply misinformed if you believe that Russia-originated propaganda has played a bigger role in the rise of right-wing extremism in Europe over the last 10 years than Rupert Murdoch (and yes, I'm aware News Corp's assets are all in English), the Anglo manosphere including the likes of Andrew Tate, and Meta, Google (Youtube) and X intentionally designing their algorithms for outrage/engagement at all costs.

Russia wishes it would have as much influence as the above.

Re: Hardware Attestation as Monopoly Enabler

#576
post #560

It's the 3rd or 4th of threads like this in the front page and it's still not clear to me what are the alternatives that privacy advocates vouch for? Dead internet theory is happening, you have botnets with more budget than most of the third world countries and you could also add openclaw usage to same bucket. There's a real need for a protocol or specification for how to attest that an action was really done by a hu…

[dead]

Re: Hardware Attestation as Monopoly Enabler

#577

Earlier quoted context omitted.

> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged

Because Apple always did this, everybody knew this and people buy Apple exactly because of this. Google now pulls the rug on Android which is a whole different story because it used to be open. The whole idea of Android was to be open.

> Google now pulls the rug on Android which is a whole different story because it used to be open. The whole idea of Android was to be open.

This is the narrative for us in developed nations, but the majority of users today are people who were in developing countries and got a mid-tier smartphone to chat with friends and do banking with the same values as Apple users.

Re: Hardware Attestation as Monopoly Enabler

#578
post #248
post #192

Earlier quoted context omitted.

You're not necessarily being surveiled just because you're forced to authenticate yourself. It often is the case practically, but it's not inherent, and mixing the two up makes the discussion too imprecise in a technical forum. Hardware attestation often also has problems of centralization, but that's something else as well. By just labeling it as an abstract bad thing without seeing nuance, I'm afraid you won't be c…

> You're not necessarily being surveiled just because you're forced to authenticate yourself. Oh hell you do! Google profit comes from ADS! It's for their profit to surveil and track and deanonymize TO SELL ADS.

A counterexample is not a valid refutation of the general point. It can be both true that Google will deanonymize you, given the chance, and that anonymous attestation is possible.

Re: Hardware Attestation as Monopoly Enabler

#579
post #248

Earlier quoted context omitted.

> You're not necessarily being surveiled just because you're forced to authenticate yourself. Oh hell you do! Google profit comes from ADS! It's for their profit to surveil and track and deanonymize TO SELL ADS.

Having thought about ads, what is the ideal feedback info channel loop from manufacturers to consumers? How best to distribute the information of who can manufacture what at what cost/price and what does it do and when is it appropriate for consumers to receive or pull info from where? And if it ends up being a monopoly of 1 centralized system how do you allow for a competitor to break through without ads?

Ads don't need to collect user information and form profiles. I don't understand why we must capitulate to more and more invasive advertising.

I don't know about you but I feel humiliated being forced to look at ads all day.

Re: Hardware Attestation as Monopoly Enabler

#580

It's so obvious to me states need to create a soul bound identity system, replace social security numbers with it, and then let everyone else use cryptography on top of that (which is now cheap when you don't care about sybil attacks) to do private stuff.

You just need to deploy auditable (source-available, reproducible-build, firmware checksums LCD on-chip) biometrics booths that generate private keys from normalized biometric inputs, and then use those ephemeral private keys to generate and sign portable identity keys. Most people have fingerprints and retina patterns and that’s twelve signatures on an identity alone, allowing for continuity across severe biometrics…

>biometrics booths that generate private keys from normalized biometric inputs

Isn't this basically worldcoin? Aside from the fact that worldcoin is run by people I wouldn't trust to watch my cats for an afternoon, the core principle with well thought out ZK crypto could work well.

Post reply on HN