Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

591–600 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#591
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

> If you want to make a meaningful contribution, however small, then make it a point to educate people about the control they are giving to large corporations like Google. This is a fool's errand. We live in a time without virtuous values, where convenience is king. The masses don't care about cookies or consent, they accept all. They only understand direct punishment.

> The masses don't care about cookies or consent, they accept all. They only understand direct punishment.

Honestly, I can totally see where the cynicism is coming from, however if you think about it, that's a pretty condescending view. This effort might be Sisyphean, but things are not as dire as you might think.

People are already seething at how much their lives are being enshitified by Big Co. Even if 10% of voters reach out to their representatives, it would be a tidal wave. Politicians are terrified of the popular will and this is not a hill they are willing to die on. Just see the success of the right to repair movement as an example.

Re: Hardware Attestation as Monopoly Enabler

#592
post #575

Earlier quoted context omitted.

You might not be from Europe then. Russia is the primary threat. They are funding extremist political movements. They are also conducting sabotage and espionage operations inside the EU.

> They are funding extremist political movements. They are also conducting sabotage and espionage operations inside the EU. These are true. They also don't have much to do with what I replied to, which was about "the propaganda efforts driving a large amount of far right nationalists into violent uprising." You're simply misinformed if you believe that Russia-originated propaganda has played a bigger role in the rise…

It obviously does. 2016 was a sterling example of the far right extremists in America fertilzing the ground for Russian influence campaigns.

They're going hand in hand, that's how fascism works, corporate interests align with government authority.

Re: Hardware Attestation as Monopoly Enabler

#593

Earlier quoted context omitted.

They factor in a more "clean" appstore yes. Not the tax itself but they usually appreciate apple having more polished apps in general (given that the Google Playstore is full of trash).

Google play store is only full of trash if you go hunting for trash. I'd like to see the actual stats of people affected by play store malware vs malware available on the play store. I'm not saying it's not a problem, but I am saying it's not a problem that has caused any problems with any Android user I've ever met.

> but I am saying it's not a problem that has caused any problems with any Android user I've ever met.

You are an HN user of some age. You might even be the family IT person. You may well be changing the experience of people in your orbit.

In contrast, my grandfather’s android phone had somehow 3 different SMS apps, all of which must have tried to remove the default app.

I doubt you think some chap living in rural India, has good data hygiene and habits.

Re: Hardware Attestation as Monopoly Enabler

#594
post #310

Earlier quoted context omitted.

I know it from personal experience using GNU tools on Sun early on (really Solaris in my case, I wasn't quite that early a user), and I think from a talk or essay by RMS but for a moment I worried it might have been personal correspondence. Finding a citation seemed like a fun challenge: https://www.gnu.org/gnu/thegnuproject.html > [...] the easiest way to develop components of GNU was to do it on a Unix system, and…

Thanks for the quote, I couldn't find anything online. Although it seems to me that the comparison is somewhat fragile : it was not possible to develop GNU anywhere else, whereas we could completely build local models from scratch nowadays, unless I'm mistaken.

Small models were originally built from distilling, using synthetic training materials, and filtering training material with much larger models. There is a bit of a bootstrapping problem where to build a good LLM you need a working LLM and if you don't have one the costs are absolutely eye watering.

One observation is that the LLM is a next token predictor but if you train it on the internet/textbooks/etc you get a predictor of that--- but that isn't the behavior we actually want. None of these sources tend to contain "Solve this problem for me. OK, here is the solution:".

It wasn't physically impossible to start GNU the other way around, by bashing machine code into a system until you had a working operating system. But doing so would have been a lot less reasonable-- much more expensive, making progress much less quickly, etc.

Re: Hardware Attestation as Monopoly Enabler

#595
post #585

Earlier quoted context omitted.

> If you want to make a meaningful contribution, however small, then make it a point to educate people about the control they are giving to large corporations like Google. This is a fool's errand. We live in a time without virtuous values, where convenience is king. The masses don't care about cookies or consent, they accept all. They only understand direct punishment.

Generalizing like this is a fool's errand, if anything. We care, and we are part of the "masses". If this is something you care about, share with others: there will be those who value it.

HN is NOT part of the “masses” in the sense “masses” is being used here.

A difference is being drawn between HN users who are interested in tech, and the everyone else. Most of humanity has little interest in Tech, and would rather spend their time on other things.

This also means they are less aware of ways to keep themselves safe, or less on top of whatever current threat is sweeping through the internet.

After multiple interactions on this site, I can say with some confidence that the average HN commenter does not have the same experience with technology that the average user does.

This divergence is resulting in different priorities and conversations.

Re: Hardware Attestation as Monopoly Enabler

#596

Earlier quoted context omitted.

One of the threat models is that a fraudster tricks a non-technical user into installing malware, which then manipulates the user interface so that next time the user tries to send money to Bob, it actually goes to Mallory. That's a legitimate concern, and one of the causes why PSD2 mandates that all 2FA devices must have a display that shows the user where they're about to send the money and how much.

And one of the threat models that police use in the US is tracking women suspected of going for abortions through the use of road cameras, and other surveillance methods. Once you have the attestation in place you have no guarantee who is going to get access to data like what apps are present on your device, and there will be nothing you can do to stop it. Meanwhile, we could educate people against common scams. How…

That's why I'm strongly against remote attestation of general-purpose hardware.

I use a handheld card reader with a display as a 2FA for my bank transactions. It shows me the transaction and, after I confirm, sends a TAN to the bank. It is not a general-purpose device but a certified, tamper-evident/-resistant black box that does just that one thing.

> Meanwhile, we could educate people against common scams.

There's a million ways you can get scammed, no matter how many hours of training you've had.

Re: Hardware Attestation as Monopoly Enabler

#597
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

[dead]

Re: Hardware Attestation as Monopoly Enabler

#598

Earlier quoted context omitted.

> Attestation purports to prove the code is running on an "approved" device. There are multiple reasons that has no real security value. BART (San Francisco Bay Area Rapid Transit), as a real world example, recently installed "evasion-proof" fare gates, and observed a 90% drop in vandalism-related maintenance expense. An overwhelming majority of fare evaders are not vandals, but apparently nearly all vandals were far…

> In other words, banks and governments and other such institutions have noticed (and they probably do have data to back this up) that very few of their customers use "unapproved" devices and a very large majority of fraud comes from "unapproved" devices. What would cause you to think that to be the case? There are two primary ways that bank fraud happens. The first is that the attacker steals the user's credentials,…

> Vandalism can be reduced by excluding fare evaders because that's a class of people rather than a class of devices.

Just observing: People who don't own an iPhone or modern android are also, generally, of a class -- and probably one banks would prefer to not do business with for profitability reasons.

People who don't have spyware/lockinware for principled reasons are currently rare enough to not matter in this analysis-- though sure, they're probably customers the bank wants.

Re: Hardware Attestation as Monopoly Enabler

#599
post #245

Earlier quoted context omitted.

The biggest problem is banking system. "Don't want - no bank for you". That's the problem.

Let them know. Write a letter to the CEO. And vote with your wallet and switch banks if you can. There's always a bank willing to offer you a non-app 2FA scheme.

> vote with your wallet

This does not work. You aren't talking about pissing off a significant percentage of the users who go elsewhere.

The imbalance in power is unthinkable to people 100 years ago when the phrase was first popularised.

Re: Hardware Attestation as Monopoly Enabler

#600

Earlier quoted context omitted.

> Why was this decision ever made? because it wasn't made the decision which was made was having a digital ID wallet, that this needs hardware attestation (or something comparable) is somewhat of a direct consequence of existing laws/regulations regarding making IDs forgery safe it also is a phone only application the huge huge majority of phones runs Googled Android/iOS, so you support them if there where a relevant…

If something is actually important, don't put it on a computer. Don't let a computer be in the critical path of anything that actually matters. It's really quite simple. Even before "AI" this technology was not reliable enough for serious, important things--systems that need to be maintainable in adverse conditions (battle damage, etc), systems where failure is not an option (proving your identity, proving your child…

> If you care about your car, truck, tractor, or dozer being maintainable and reliable, don't get one with a computer in it.

Got a list of widely available cars and trucks 'without a computer'? :D

Post reply on HN