Live data from Hacker News

Hardware Attestation as Monopoly Enabler

grapheneos.social

781–790 of 799 posts

Re: Hardware Attestation as Monopoly Enabler

#781
post #530

Earlier quoted context omitted.

If proof of work is the "payment" to prove that you're human, many AI startups will outbid poor people living third world countries. They will even outbid some Americans. Yes, those AI startups can also buy cheap Android phones at scale, but it's a bit harder because they'll pay for stuff that their bots have no use for (a screen, a battery, a 5G radio, software, branding, distribution, customer support etc).

> If proof of work is the "payment" to prove that you're human, many AI startups will outbid poor people living third world countries. They will even outbid some Americans. The difference is that if you're human you can create an account and then carry on using it for decades, whereas if you're an aggressive scraper bot or spammer then you get banned and have to buy new accounts over and over.

An "account" which is somehow linked to enough of your browsing history to determine if you're a scraper or a spammer. Then the company(s) administrating these accounts will be able to collect a lot of info on the account holders over decades.

Google hardware attestation idea won't give them that much data: All Google will know is which phones visited which websites and only when the website asks the phone for hardware attestation. If the website gives the phone a cookie for bypassing subsequent attestations, then Google will know only of the first visit.

Re: Hardware Attestation as Monopoly Enabler

#782
post #300

Earlier quoted context omitted.

Yes, comrade, those newsletters should be disposed because of evil foreign pяopoganda

I'm zorry, have you slept through brexit, january 6th, racist anti immigration campaigns and torture prisons? Are you just not paying attention to the dissolution of democracy or are youjust like, cool with money being the only protected thing.

Your point is valid, however govt(corrupt officials) keeping power over freedom of information will end very bad.

Re: Hardware Attestation as Monopoly Enabler

#783

Earlier quoted context omitted.

> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged

Apple is the classic “good king”. By and large they have used their power in ways that benefit users. Other than enriching apple, there’s been no direct or apparent harm to the end user from the walled garden. I know that is a controversial point, but harms we don’t ever know about are pretty hard to get upset about. But the “good” king never lasts. They’re always eventually replaced by a despot, and all the power yo…

> Other than enriching apple, there’s been no direct or apparent harm to the end user from the walled garden.

https://www.reuters.com/sustainability/society-equity/apple-...

I don't want to hear about how this isn't Apple's fault. This isn't the big bad orange man forcing Apple to act against its will; it's a business arrangement between Apple and the president. He gets censorship, they get a weaker EU.

https://www.whitehouse.gov/presidential-actions/2025/02/defe...

Re: Hardware Attestation as Monopoly Enabler

#784

Earlier quoted context omitted.

On principle I agree with you. And for me I totally want that, in part because I know how to take care of myself and avoid phishing (I got pwned once, but thankfully it was my company’s honey pot, not actual phishing). Many people aren’t like us. Give them freedom to chose their password without mandating 2FA, and some will lose money to a password database leak & offline guessing. The policy maker knows this, at whi…

> they have a choice: stricter annoying rules with fewer victims, or looser rules with more victims? Yep, there's a reason freedom vs safety (or libertarianism vs authoritarianism) is an axis on many political spectrum charts. This is a very common source of tension in politics. As you can probably guess, I usually find myself on the libertarian side of such debates. Freedom is worth the price. > Give them freedom to…

> Freedom is worth the price.

I generally lean towards that too, including for this issue. But we do need to own up to it. Explicitly ask ourselves, what kind of bad consequences, and how much of them, are we willing to put up with in the name of freedom?

Also, some framings make it difficult: the second someone speaks of protecting the children, all of a sudden freedom becomes secondary. Which leaves two counters, which are logically compatible, but tend to be rhetorically exclusive: denying that this new thing will actually protect the children; and asserting that the protection it allegedly provides is not worth the loss of freedom.

The second one is a hard sell, which is why we so often revert to the first one. Take age verification: sure it won’t stop determined underage teens from seeing images of bunny girls. But it will deter some of them. And assuming images of bunny girls are bad for teen health, it means age verification does "protect the children". A little. And voilà, we’ve destroyed the argument that age verification does absolutely nothing, mass surveillance for the win!

> […] which I don't think is an acceptable thing to do to mentally sound adults.

I haven’t thought of the psychological damage over-protectiveness may cause. That’s a bloody good point.

> There's plenty of competition in the banking space,

Given how people in some countries complain that it’s difficult to find a bank that doesn’t require a locked down phone for online payments, I would argue perhaps not plenty enough. I totally agree though that for any bank to require one of two OSes is not good, and for this reason would be tempted to outlaw such requirements (thus reducing corporate freedom, but I care more about individual freedom).

> some sort of software freedom law guaranteeing users the right to modify software running on devices they own.

That is very tempting indeed. Do understand though that such a law comes very close to mandating Free Software everywhere: for this right to be effective, users need access to the source code, and be allowed to let some professional modify that code for them. Any mass produce piece of hardware would effectively have to publish the full code source of their drivers for all to see. I would absolutely love that, but NVDIA would likely lose their marbles over this.

Re: Hardware Attestation as Monopoly Enabler

#785

Earlier quoted context omitted.

> No I mean that the operating system protects applications from messing with each other. The operating system should isolate each app for security purposes. Oh but that is far incomplete a specification. What security purposes? Who are we protecting, from whom? On whose behalf does the OS isolates applications from each other? If it’s on mine, then you bet I absolutely want the ability to lift that isolation in spec…

In short the integrity of the application must be secured. This integrity must be protected from everyone. Nothing should be able to violate the integrity of the app. >I absolutely want the ability to lift that isolation in specific cases. There is no need for this. Allowing end users to turn off security features is not a good idea. Users should not have to think about such things. >I decide when and how the rules a…

> In short the integrity of the application must be secured. This integrity must be protected from everyone. Nothing should be able to violate the integrity of the app.

I’m getting a strong sense that you don’t know what you’re talking about. "Everyone" for instance doesn’t include the app vendor. You want to allow updates, right?

> Most users do not want this ability

Again with the ambiguous wording. What do you mean exactly? That >50% of users don’t care about having this ability, or that >50% of users explicitly reject this ability?

In my experience, most users think they don’t care, until they need to run an app that’s not on the main app store. Easy example: skip YouTube ads. On Android, you jumps a few hoops, install Newpipe or Tubular, and voilà, no more ads. But I’ve met several iPhone users who wanted the same, and were quite dejected when they realised they couldn’t have it.

Of course, the idea that most users explicitly reject the ability to bypass security measures is utterly ridiculous.

> Allowing end users to turn off security features is not a good idea.

Not that I’m not talking about flipping a switch that would end all process isolation. I’m talking giving permission to one app to mess with one other app. Secure by default with fine grained permissions, not "please revert to Windows 98 with zero memory protection".

> Users should not have to think about such things.

They have to anyway. Where their credentials are, what if they break their computer, lose their phone, their data gets leaked…

Re: Hardware Attestation as Monopoly Enabler

#786
post #716
post #633

Earlier quoted context omitted.

is that tyrant in the room with us now?

We are a generation of tyrants, each oppressing the others in his own little domain. Gone is the dream of making a modest living while enriching humanity with offerings of technology. Whatever is invented now is gated, rented, and exploited for power, in the shadows and in the open, and what technological power had been granted to the people is whittled away year by year, immense riches destroyed so someone in partic…

By the way, this paints a very dark picture. I keenly mourn the world I feel slipping away, but there are bright spots and people who fight the good fight, and the occasional blessed and beautiful creation and the odd victory. I don't mean to imply these things are pointless or hopeless - on the contrary. People who do that are the reason we have any good things at all. Thank you.

It is not an us vs. them sort of thing. Don't get me wrong, there are wicked people doing awful things, but I breathe the same air everyone else does. I remember building things 20 years ago with breathless excitement about how it might make the world a better place, and these days I am much quicker to think about how to monetize. Asking a fair price for something isn't evil, but none of us is an island and I don't like how my dreams have changed. I write these things in part to teach myself.

Re: Hardware Attestation as Monopoly Enabler

#787
post #528

The superhuman efforts that folks on HN make to find technical workarounds and solutions is wonderful to see, but we must realize that this is not a technical problem. It's a social and legislative one. It can't be fought on technical grounds. The push back has to be via putting pressure on politicians by making regular people more aware. Right now, the vast majority of users are being bombarded with a one sided narr…

> In my experience, once the issue is framed as 'Google will decide what you can do with your phone' every single person is immediately outraged. Apple already does this and practically no one is outraged

And it was a huge mistake. The laws are the same for everyone. If Apple can do this then so can Google.

Re: Hardware Attestation as Monopoly Enabler

#788
post #504

I always say this when this topic comes up: remote attestation will be how our computing freedom dies. They've made it so that it doesn't even matter if they allow you to install whatever you want. Anything that isn't corporate owned is banned. Own your device? You "tampered" with it. You're banned. From everything. You're ostracized from digital society. You're not even a citizen, much less a second class citizen. E…

I think it's quite telling that this comment was written in Brazil. The so-called Third World is the future source of freedom (or Western countries that become third world perhaps). It may not be a bad idea now to start building open compute and banking alternative ecosystems based in those countries, marketed at Western citizens.

The third world is also pushing Digital ID. In fact they would love it even more than the first world as it would allow for even more totalitarianism.

Re: Hardware Attestation as Monopoly Enabler

#789

With all of the discourse around hardware attestation, digital ID, and age verification in recent weeks/months, is there actually any good solution to the problems these existing tools (Privacy Pass, WEI, Fraud Defense, uploading IDs) claim to solve? Are there open and privacy-preserving standards that can solve the problem of bots and minors? If not, what would be required to establish one, and is it realistic? Busi…

The people pushing for age verification have already said that they want to know who's behind every account on every website on the entire Internet. They won't accept any open or privacy-preserving standard.

Re: Hardware Attestation as Monopoly Enabler

#790

Earlier quoted context omitted.

Never trust user input. The users already can't modify the server. And what actual applications did you have in mind that warrant throwing everybody under the bus? (by that I mean some applications (allegedly) need it, so it gets forced on everyone)

My banking app already trusts Face ID right now!

And how is that necessary? It's a convenience feature, nothing more. You might as well trust your bank with your biometric data directly, and leave me and others out of it either way. Even IF there was a real need for a mobile device with which general computing is not possible, that would not justify killing it everywhere just so people who do need it can "just use their phone".

That the laziest of us don't mind and the worst of us want something is not a respectable argument for anything, ever.

Post reply on HN