Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

741–750 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#741

Earlier quoted context omitted.

I have 2 servers, Alice and Bob, Bob has a secret, I want Bob to be able to share that secret with Alice. However, I want Alice to be able to prove to Bob that it is actually Alice, that it is running the correct AliceOS, and that AliceOS was loaded on bare metal Alice without nefarious pre-book or virtualization hooks. A TPM with measured boot (SecureBoot) does exactly this, remote attestation is how Alice proves to…

That's the academic viewpoint, but in practice it's used for far more hostile purposes. (One argues that since you own both of them, you should simply set up the two servers yourself with a key of your own choosing, asymmetric or otherwise, and then restrict physical access to them.)

It's not academic, it's a real practical reality.

Alice runs many services and has a rather large attack surface. I don't want Alice to persist those secrets, only to have them briefly at startup (think joining tokens). Bob however has exactly one job, verify that Alice-1 to Alice-N are in a trusted configuration before granting them access to the cluster.

Very recent events in the Linux kernel prove that it isn't safe to assume "0600 root:root" is sufficient to protect secrets from a misbehaving container.

Re: Hardware Attestation as Monopoly Enabler

#742

Earlier quoted context omitted.

> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged

Because Apple always did this, everybody knew this and people buy Apple exactly because of this. Google now pulls the rug on Android which is a whole different story because it used to be open. The whole idea of Android was to be open.

People do not buy Apple because of this. They buy Apple for other reasons and this comes along with it. Apple could allow side-loaded apps and not a single person would switch

Re: Hardware Attestation as Monopoly Enabler

#743

Earlier quoted context omitted.

To defend my own freedom, I'm forced to defend scoundrels as well in a totally unhinged manner. So be it. > the operating system is unable to attest And it should remain unable. There should be no "attestation" of anything. The corporations who want such things should remain unsure of the device's "security". They should just accept it. Let them write it off as a cost of doing business or something. The optimal amoun…

I don't see any consumer nor developer demand to make cheating in multiplayer games an inherent tenant of a computing ecosystem. Attestation is just an optional feature that expands what is possible. Services have no obligation to check attestation or use it as a hard signal to block people. All previously existing freedom is still possible on your computer.

> Attestation is just an optional feature that expands what is possible.

So optional that everything that can require it will require it. Games want it because cheating. Streaming services want it because piracy. Banks want it because fraud. Web sites want it because advertising. Governments want it because encryption and anonymity.

> Services have no obligation to check attestation or use it as a hard signal to block people.

They will do so of their own free will.

> All previously existing freedom is still possible on your computer.

You're "free" on your paperweight of a computer that can't do anything useful because it can't interface with the rest of society. Maybe one day even ISPs will reject clients that can't pass attestation. Can't even join the internet if you "tampered" with your machine. Such is life in the land of the free.

Re: Hardware Attestation as Monopoly Enabler

#744
post #696
post #693

Earlier quoted context omitted.

Please explain what makes them good? They make a better product than most, but they also charge more than most. That's just a business model.

For one thing, Apple has tended to focus on privacy at the expense of profit. Apple could certainly be monetizing all of their user data. Now more than ever. It's not just businesses that want your data to sell you stuff, it's the hyperscalers wanting to funnel it into AI training. Apple is not perfect, by any means. I recently had a conversation with a former Apple employee about how they employ differential privacy…

>For one thing, Apple has tended to focus on privacy at the expense of profit.

A company reveals its priorities when it is forced to make inconvenient choices. What privacy compromises did the CCP force out of Apple in exchange for doing business in China?

Re: Hardware Attestation as Monopoly Enabler

#745
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

[deleted]

Re: Hardware Attestation as Monopoly Enabler

#746
post #716
post #633

Earlier quoted context omitted.

is that tyrant in the room with us now?

We are a generation of tyrants, each oppressing the others in his own little domain. Gone is the dream of making a modest living while enriching humanity with offerings of technology. Whatever is invented now is gated, rented, and exploited for power, in the shadows and in the open, and what technological power had been granted to the people is whittled away year by year, immense riches destroyed so someone in partic…

[deleted]

Re: Hardware Attestation as Monopoly Enabler

#747
post #2

This is a really good thread on why this technology is becoming a problem for "open" anything. The argument "we can create our own separate web" is fine until all of your services are behind the web that locks you into owning a Google approved or Apple approved mobile device.

I like to ride my bicycle with my friends in rides organized by the (Pacific Northwest) Cascade Bicycle Club. They require that I solve a Google reCAPTCHA in order to register for a ride. Google is already completely locking me out from being able to do that. When I try to click on the squares to select whatever items it's asking, it indefinitely loops. When I try using the audio version, it completely blocks me from…

The old, open web is too easy to attack and that is part of what has led sites to adopt technologies like this. I hope there are better solutions than everyone-is-their-GoogleID, but how realistic is it that people just trying to run a bakery, a bicycle ride, &c, will find them? They have other things to do.

Re: Hardware Attestation as Monopoly Enabler

#748

Earlier quoted context omitted.

> People don't actually believe every car should have a GPS tracker so that if a pedophile drives a car, the police can track it. It's not about what people believe, but what they are willing to publicly push back against. If such a law was proposed today, I bet it would pass because the only discussions around it would be whether the data can be kept safe and what punishments to dole out if the car owner access this…

This was already in place in the EU back in 2024. Lookup DDAW. You can turn off warnings, but it will still keep on monitoring the driver

Wow!

https://seeingmachines.com/understanding-driver-drowsiness-a...

Since July 2022, Driver Drowsiness and Attention Warning (DDAW) systems have been required in all new vehicle types within the European Union (EU). They will be mandatory for all newly registered vehicles from July 2024.

Re: Hardware Attestation as Monopoly Enabler

#749

With all of the discourse around hardware attestation, digital ID, and age verification in recent weeks/months, is there actually any good solution to the problems these existing tools (Privacy Pass, WEI, Fraud Defense, uploading IDs) claim to solve? Are there open and privacy-preserving standards that can solve the problem of bots and minors? If not, what would be required to establish one, and is it realistic? Busi…

Thank you for offering this take -- it is the only forward looking one.

The anonymous internet is going away -- it is too supportive of crime and various kinds of gray area misconduct, and governments and large corporations were eventually going to do something about that.

Such a degree of anonymity is desirable, but it is not a requirement for a free society. What were things like before the internet? You couldn't anonymously browse billions of pages of information in 1960.

Re: Hardware Attestation as Monopoly Enabler

#750
post #574

Earlier quoted context omitted.

> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged

Frame it as "America will decide what you can do with your phone" and people in Europe will listen.

Frame it as "the government will decide what you can do with your phone" and people in America will listen.
Post reply on HN