Earlier quoted context omitted.
One of the threat models is that a fraudster tricks a non-technical user into installing malware, which then manipulates the user interface so that next time the user tries to send money to Bob, it actually goes to Mallory. That's a legitimate concern, and one of the causes why PSD2 mandates that all 2FA devices must have a display that shows the user where they're about to send the money and how much.
And one of the threat models that police use in the US is tracking women suspected of going for abortions through the use of road cameras, and other surveillance methods. Once you have the attestation in place you have no guarantee who is going to get access to data like what apps are present on your device, and there will be nothing you can do to stop it. Meanwhile, we could educate people against common scams. How…
Hardware Attestation as Monopoly Enabler
601–610 of 799 posts
Re: Hardware Attestation as Monopoly Enabler
#602Earlier quoted context omitted.
Generalizing like this is a fool's errand, if anything. We care, and we are part of the "masses". If this is something you care about, share with others: there will be those who value it.
HN is NOT part of the “masses” in the sense “masses” is being used here. A difference is being drawn between HN users who are interested in tech, and the everyone else. Most of humanity has little interest in Tech, and would rather spend their time on other things. This also means they are less aware of ways to keep themselves safe, or less on top of whatever current threat is sweeping through the internet. After mul…
Edit: I think that, given that us HNers often self-identify as tech priests, advocacy and education should follow naturally from that.
Re: Hardware Attestation as Monopoly Enabler
#603The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…
Nope. It's not the issue. The issue is people genuinely want the security problem to be solved by someone else. Either governments or big companies. So they can just not care about security once and for all.
If people were so aware of so-called hackers and how insecure their devices are, we would have seen people stopped installing apps on their phones and basically use it as a web browser. But that's not what happens. The opposite is truer: if you run an even slightly popular website you will receive feedback asking if you have an app version.
> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged.
Oh boy, you're going to be really surprised.
Re: Hardware Attestation as Monopoly Enabler
#604Earlier quoted context omitted.
It's not about being secure. Google allows devices with up to 10 years without any patches to pass their integrity API. Meanwhile Graphene OS, which is very secure and up-to-date, doesn't pass.
This. Plus if I want to access my bank account on a device I trust , the bank shouldn’t say “hey we don’t trust it so buzz off”. It’s my money in that account. I understand there’s some stupid compliance thing that makes banks do this, but it clearly isn’t a hard requirement, as there’s still plenty of banks that don’t participate in this security theatre.
Re: Hardware Attestation as Monopoly Enabler
#605Earlier quoted context omitted.
Hell yes. I was going to post the same comment. I don't give a flying fuck how it's implemented. Remote attestation is inherently evil. I remember the WEI apologists trying to do the same thing to derail the argument. The problem is the goal, not the details. Just say no: DO NOT WANT!
Remote attestation is a technology, not a policy or a political effort, so it can't be inherently evil. You can disagree with all its known or proposed uses, but then I think it makes more sense to name these.
Suppose someone invents a mind-reader that lets the user read the thoughts of anybody else in range. But the mind-reader requires great up-front costs to produce and also allows people with stronger readers to remotely destroy weaker readers, where strength is basically a function of cost.
In a vacuum, the mind-reader is "just a technology". But it aids autocratic surveillance much more than it aids citizens who want to surveill back. It's "neutral" but its impact is decidedly not.
TPMs and remote attestation enable entities with power to enforce their existing power much more effectively. In contrast, a general-purpose computer does the opposite because anybody can run whatever code they want, they can adversarially interoperate with anybody they feel like, and so on.
One of these is more evil than the other, even though they're both "just technologies".
Re: Hardware Attestation as Monopoly Enabler
#606Earlier quoted context omitted.
> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged
Yes, but most people don't realize it, simply because they have been conditioned from the beginning that the only way to run anything on an iOS device is via the app store. With Apple customers, a better argument to make is to say that Apple applies a 30% 'tax' on all activity on their phones. That they are being forced to pay more compared to non Apple users in spite of having bought their device fair and square.
Re: Hardware Attestation as Monopoly Enabler
#607Seems to me like Microsoft might be opposed to this duopoly and have pockets deep enough to fight it, right? For one, this would make their possible re-entry into the mobile space harder and more costly but I guess it'll inevitably become a standard that other providers could fulfill.
On the contrary, Microsoft was one of the early promoters of such technology; look up Palladium/TCG/NGSCB.
Re: Hardware Attestation as Monopoly Enabler
#608Earlier quoted context omitted.
Ideally, we just run our own lives, collaboratively. That's the anarchist default position that we all start in. What we really need is to meaningfully participate outside of the hierarchical monopolistic systems that demand our participation. That doesn't just mean that we create and hang out in distributed networks: it also means that we make and do interesting shit there, too. The biggest hurdle I see is that we o…
but what if the alternatives are fundamentally worse ? Turns out centralization has a lot of advantages. I think it's an error to demand the alternatives be as good-- that might not even always be possible. But even if they're less good they're usually still better than anything we could have imagined decades ago-- they're good enough to use. And that should be enough because we shouldn't consider handing control of…
I think the main struggle is moderation. Moderation requires a hierarchy, which is much more compatible with a centralized model. I'm thinking that curation would be a good alternative. Rather than authoritatively silencing unwanted content, just categorize it well enough for users to filter what they want.
Re: Hardware Attestation as Monopoly Enabler
#609The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…
> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged
The solution should be to provide the tools necessary to preserve as much agency using technology to people who want to. You should also keep in mind the middle tier technical people who need a bit of hand holding. But do not waste your time on the general public because they don't share or comprehend your goals.
Re: Hardware Attestation as Monopoly Enabler
#610Earlier quoted context omitted.
No? Apple charges a fee on every app sale. Where do you think the app makers pay that walled garden tax?
Never spent money on an app on my phone.