Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

611–620 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#611
post #555

Earlier quoted context omitted.

> Passkeys absolutely do not need TPM. They do not, but how does the service you’re using know your passkey is secure? For all they know you’re just some gullible user that clicks through every fishing email you get. You’re dumb, weak, helpless, they gotta protect you from this scary world out there, and maybe yourself as well. They can’t do that if they allow your passkey to be stored anywhere you control. KeepassXC…

> For all they know you’re just some gullible user that clicks through every fishing email you get. Passkeys are non-phishable. That's part of their schtick. I'm not a huge passkey fan myself, but this is a real benefit.

Yes, but that’s not the threat model I was alluding to. The threat model was, you get tricked into executing malware, that will steal your passkey (and your entire password database in fact), and log your master password as soon as you use it.

When the passkey is protected behind an HSM (TPM, Yubikey, Tkey…), even a compromise of your main computer can’t steal it. Attackers can still temporarily log in on your behalf, but they can’t do anything with your passkey as long as your computer is turned off. Which means you can un-pwn yourself out of this situation by reinstalling everything (but do keep your HSM!).

Overall, we have several levels of security here:

- Weak password, (potentially reused everywhere). Fished once, pwned everywhere. Not to mention password database leaks.

- Very strong unique password from your password vault (KeepassXC). Note that with automatic login, password managers may provide good phishing resistance. Manual copy pasta is still vulnerable, but at least you only compromise that one account.

- Passkey stored in your password database. Phishing proof as you say, but falls to a keylogger.

- Passkey sorted in a hardware security module. Can’t be stolen ever, save for a vulnerability in the HSM itself, or, if you haven’t set up a password for your HSM, theft.

Clearly that last option is the most secure. Clearly it would be nice if everyone could do that, though we do need a way to recover from the loss or destruction of the HSM (which in the case of the TPM may mean something as mundane as changing your graphics card). Yet often, other ways are more convenient.

Still, I strongly believe companies should not force people into one method or another. Okay, I could maybe tolerate passkeys being forced on me, but not the remote attestation part. Let me manage my own security, with my own tools (preferably open source), thank you very much. There is one use case for which I may approve of remote attestation: work accounts. Because at this point it’s not about the safety of the customer, it’s about the safety of the company itself. It makes sense then that the company (or government agency) impose whatever stringent restrictions on how to access their network. They do have to provide any required tool (company laptop, company palmtop, company dongle…), same way many companies are required to provide individual safety equipment to any of their employees working in hazardous environments.

Re: Hardware Attestation as Monopoly Enabler

#612
post #530

Earlier quoted context omitted.

I'm as biased against cryptocurrency as everyone, but couldn't we have the requestor do a bit of mining work to mint that initial id? I mean, if the service is actually making a bit of money from each request, the need for rate limiting just vanishes, right?

If proof of work is the "payment" to prove that you're human, many AI startups will outbid poor people living third world countries. They will even outbid some Americans. Yes, those AI startups can also buy cheap Android phones at scale, but it's a bit harder because they'll pay for stuff that their bots have no use for (a screen, a battery, a 5G radio, software, branding, distribution, customer support etc).

A least they would give money to something useful.

Re: Hardware Attestation as Monopoly Enabler

#613
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

I think part of it is the hackers that the media reports on are entirely malicious. Most hackers aren't, we just like computers

Re: Hardware Attestation as Monopoly Enabler

#614
post #555

Earlier quoted context omitted.

> For all they know you’re just some gullible user that clicks through every fishing email you get. Passkeys are non-phishable. That's part of their schtick. I'm not a huge passkey fan myself, but this is a real benefit.

Yes, but that’s not the threat model I was alluding to. The threat model was, you get tricked into executing malware, that will steal your passkey (and your entire password database in fact), and log your master password as soon as you use it. When the passkey is protected behind an HSM (TPM, Yubikey, Tkey…), even a compromise of your main computer can’t steal it. Attackers can still temporarily log in on your behalf…

Yes, I agree that device-bound credentials (DBC?) are a really big deal here. Just wanted to get the story straight.

When it comes to the notion of requiring DBCs without also requiring remote attestation, how do you deal with solving the problem of virtualized credential devices, e.g. swtpm? If some application wants to leverage DBCs, it will make some DBC API call, e.g. call out to a TPM. However, without some sort of attestation scheme, there's no way to verify who/what is on the other end of that API call.

Maybe it's not important for applications to be able to require DBCs without attestation. But at first blush it seems like a valid thing to want.

Re: Hardware Attestation as Monopoly Enabler

#615

Earlier quoted context omitted.

Requiring "tokens" stored in "trusted modules" and 7-factor-auth for everything is not progress, it's theater. The biggest achievement of the security orthodoxy was locking me out of my email, by requiring me to read a code sent to my email to log into my email. I -- literally -- do not care about a single "account" in any "service" I use aside from my email and bank account. Most people would add a few social media…

What about Apple Wallet? The reality is that there is software dependent on the user being unable to modify it. This safeguards the server against fraudulent users.

The one that's so incredibly broken that Apple and Visa keep blaming eachother when they get a report that you can steal any amount by making yourself pass as a transit card ? Cool security theater. https://hackernoon.com/veritasium-stole-$10000-from-mkbhds-l...

Re: Hardware Attestation as Monopoly Enabler

#616
post #530

Earlier quoted context omitted.

I'm as biased against cryptocurrency as everyone, but couldn't we have the requestor do a bit of mining work to mint that initial id? I mean, if the service is actually making a bit of money from each request, the need for rate limiting just vanishes, right?

If proof of work is the "payment" to prove that you're human, many AI startups will outbid poor people living third world countries. They will even outbid some Americans. Yes, those AI startups can also buy cheap Android phones at scale, but it's a bit harder because they'll pay for stuff that their bots have no use for (a screen, a battery, a 5G radio, software, branding, distribution, customer support etc).

As I see it, living requires money. If we have people on this planet that are too poor to digitally prove that they're alive, then we need to figure out a way to distribute the Earth's wealth more equally in general, rather than to require hardware attestation, which seems to be worse on essentially every metric, including inequality.

Re: Hardware Attestation as Monopoly Enabler

#617

Earlier quoted context omitted.

Google play store is only full of trash if you go hunting for trash. I'd like to see the actual stats of people affected by play store malware vs malware available on the play store. I'm not saying it's not a problem, but I am saying it's not a problem that has caused any problems with any Android user I've ever met.

I am not talking about the malware, I am talking about the apps that are bloated with advertisements or try really hard to push a subscription upon you. Lots of "free" apps try to push you into a subscription once installed.

By that measure, the Apple app store is full of trash too.

Re: Hardware Attestation as Monopoly Enabler

#618
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

I think part of it is the hackers that the media reports on are entirely malicious. Most hackers aren't, we just like computers

Evil people always get in the news.

Sadly much as I agree with OP, the reality is there are a lot of evil people, and some of them lead a country and thus have vast resources to attack with. We need to solve this problem, not just cry about what a few of us are losing.

Re: Hardware Attestation as Monopoly Enabler

#619
post #530

Earlier quoted context omitted.

If proof of work is the "payment" to prove that you're human, many AI startups will outbid poor people living third world countries. They will even outbid some Americans. Yes, those AI startups can also buy cheap Android phones at scale, but it's a bit harder because they'll pay for stuff that their bots have no use for (a screen, a battery, a 5G radio, software, branding, distribution, customer support etc).

A least they would give money to something useful.

Attestation is a service, like every other service. Why should it necessarily be free? Especially now that we all know that "free" on the web means ads & tracking?

I think we should just accept that some things should cost a bit of money and move the discussion to "how much should it cost", rather than trying to sweep economics under the rug.

Re: Hardware Attestation as Monopoly Enabler

#620

Earlier quoted context omitted.

Can you show me examples where locking down an OS has prevented fraud in banking? Honestly, if the only way to secure your banking system is by locking down users' devices, there is something really bad going on at your end, security-wise. Your system should be secure even without locking down user hardware.

Look at the last 30 years of computing history? When online banking was first created it was an absolute chaos zone. Everyone was accessing it from desktop machines riddled with viruses and malware. There are endless stories of being discovering their life savings had been wired to Belarus by some malware running on their machine that had grabbed their banking credentials when they logged in. https://www.google.com/s…

>....the calculator devices were retired in favour of smartphones with remote attestation. This was better in literally every way, for 100% of users.

Not 100%. A robber can force people to activate facial recognition or finger print sensors. Forcing someone to type a pin code is harder but doable. If one doesn't bring the authenticator & bank card they cant initiate transactions.

Post reply on HN