Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

61–70 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#61
post #6

Our civilization desperately needs a method to modify modern microelectronics after manufacturing that can be used at least in a well-equipped repair shop, and it needs it yesterday. Alternatively, just make it illegal to ship any kind of initial bootloader as part of a CPU's/SoC's mask ROM in any computing device that is marketed as a general-purpose one. I.e. the first instruction that the CPU executes after reset…

> just make it illegal to ship any kind of initial bootloader funny how you think the solution to people imposing their will on you is to impose your will on others also, the solution you propose wouldn't work because signed firmware

And what code will verify the signature of the initial bootloader? As far as I know, in every modern implementation of secure boot that is done by that very bootloader, which is burned into the CPU/SoC. I can imagine someone implementing some sort of fixed-function block to do that, but see my sibling reply about that.

Also, governments are supposed to act in the interest of people.

Re: Hardware Attestation as Monopoly Enabler

#62

Earlier quoted context omitted.

If you live in a democracy, you already do run your own country. Vote accordingly. Get involved in politics.

There are mountains of academic research showing that even in “democracies”, public opinion rarely translates into policy (by design).

https://www.nber.org/papers/w29766

Stop re-electing people.

Stop sitting at home projecting apathy and ennui in between WOW raids and rounds of LoL.

Mountains of evidence from history shows public has to stand up for itself, not lick boot.

Refuse to give the politicians and owner class assurances they too refuse to provide.

Most of them are old af and have no survival skills. They're reliant on the latest social memes, stock valuations not religious allegory, that are not immutable constants of physics.

Boomers looted the pension system of the prior generation to fund Wall Street. Take their money. It's American tradition.

Remind them physics is ageist and neither physics and American society afford no assurances anyone has food and healthcare.

Re: Hardware Attestation as Monopoly Enabler

#63

It is definitely a monopoly enabler. But also a threat to speech. You can only participate online if you have attested hardware. And that hardware will be tied back to you. It’s another threat to privacy like age verification laws.

Safety is the pretext. This is the actual reason why this is happening, and why it is accelerating now

Re: Hardware Attestation as Monopoly Enabler

#64

Earlier quoted context omitted.

> Am I understanding correctly that [...] What I took away from the thread is that they're against services forcing attestation in general, and also pointing out that Play Integrity isn't about security, but rather about control, because Google could trivially make it work with GrapheneOS (which is more secure than any other Android OS on the market) but they won't.

> …Google could trivially make it work with GrapheneOS (which is more secure than any other Android OS on the market) but they won't. But if Google did support third-party attestation, would the GrapheneOS Foundation be happy? Most of the thread seems to be a call for attestation to die, which feels impractical and unachievable. But "Google could use it to permit GrapheneOS for Play Integrity if that was actually abo…

No. That would be a relatively better circumstance, but we would still have the root problem.

> Most of the thread seems to be a call for attestation to die, which feels impractical and unachievable.

I disagree, and I expect GrapheneOS devs do, too. Hardware attestation is a new thing, that isn't even really here yet. It absolutely can and should meet its demise.

Re: Hardware Attestation as Monopoly Enabler

#65
post #4

Earlier quoted context omitted.

I disagree, I think you cast the net way too wide. Asymmetric cryptography enables secure communication in the first place. It's being used nefariously by Google and Apple, of course, but that's to be expected from big tech.

Nefariously how?

Remote attestation also uses asymmetric cryptography. (Device-bound private key that can sign attestation challenges, a known public key that can verify that challenge was signed with the device-bound private key.)

Re: Hardware Attestation as Monopoly Enabler

#66

The EU Digital (identity) Wallet EUDI requires hardware attestation by Google or Apple, effectively tying all the digital EU identities to American duopoly. Talk about digital sovereignity. Apparently protecting the children > sovereignity. https://gitlab.opencode.de/bmi/eudi-wallet/wallet-developmen...

So with a single flip of the switch, the president of the USA can shut down our EU Digital Identity Wallet.

Why was this decision ever made?

Re: Hardware Attestation as Monopoly Enabler

#67
post #58

Earlier quoted context omitted.

This won’t help; the SOC silicon can be revised to record each executed instruction from power-on until secure-boot handoff opcode, with various supporting opcodes to query status-of / overflow-of / signature-for so that the OS reports pre-boot tampering implicitly as part of developing its own attestations.

Then also make it illegal for the SoC to contain any cryptographic key material. My intention with this is to make sure that if someone were to desolder the flash chip and reprogram it, they could completely own the device without the device or SoC manufacturer having a say in it or a way to prevent or detect it.

Simpler to just make discrimination by hardware or software illegal than to legislate the silicon contents. That’s what everyone is upset about, after all: websites are gaining the ability to discriminate based on hardware-software with specific fidelity they never had before. If that was made unlawful, then you’d benefit billions of existing devices as well as future ones. The hard part is making the case that this sort of discrimination is worth fighting, but the John Deere lawsuits are (indirectly) further ahead on that point than the rest of tech is, weirdly enough.

Example: I’m perfectly fine with my Touch ID sensor having a crypto-paired link to my SOC so that someone can’t swap in a malware-sensor at a border checkpoint; I also don’t want my device (or websites) to be able to discriminate against me installing my own homemade sensor. What that looks like in practice is close to what we have now, but not quite there yet — and is definitely not ‘no crypto-pairing at all’, as a ban on key material would enforce.

Re: Hardware Attestation as Monopoly Enabler

#68
post #27
post #8

Earlier quoted context omitted.

It's not asymmetric cryptography itself. It's the fact that it takes enormous resources to manufacture modern SoCs, such that the economy only makes sense if you're churning them out by millions at least. It's also the fact that they can't be modified after they've been manufactured. It's basically those people who can manufacture chips having technological supremacy over the rest of the humanity.

It doesn’t matter if you can produce SOCs if your hardware isn’t trusted.

What if you can copy someone else's SoC including their keys?

Re: Hardware Attestation as Monopoly Enabler

#69

It's so obvious to me states need to create a soul bound identity system, replace social security numbers with it, and then let everyone else use cryptography on top of that (which is now cheap when you don't care about sybil attacks) to do private stuff.

Any system mandated by the government will have a backdoor to deanonymize users. Nothing would convince me otherwise.

Re: Hardware Attestation as Monopoly Enabler

#70
post #6

Our civilization desperately needs a method to modify modern microelectronics after manufacturing that can be used at least in a well-equipped repair shop, and it needs it yesterday. Alternatively, just make it illegal to ship any kind of initial bootloader as part of a CPU's/SoC's mask ROM in any computing device that is marketed as a general-purpose one. I.e. the first instruction that the CPU executes after reset…

> just make it illegal to ship any kind of initial bootloader funny how you think the solution to people imposing their will on you is to impose your will on others also, the solution you propose wouldn't work because signed firmware

It's called laws
Post reply on HN