Live data from Hacker News

What happened to running what you wanted on your own machine?

hackaday.com

91–100 of 315 posts

Re: What happened to running what you wanted on your own machine?

#91

It's important to understand that we could genuinely lose general purpose computing. I don't think it's in serious danger at the moment, but we've been in the midst of a slide in that direction for the last 10-15 years. Part of it is mobile phones, part of it is TPM, part of it is market forces. The latest turn is strictly political. We've really foolishly built the technology necessary for authoritarianism just a fe…

So it's just about incentives right? Who has the power to make these decisions, and what are they likely to decide, given their incentives?

Re: What happened to running what you wanted on your own machine?

#92

Earlier quoted context omitted.

I have an ugly hunch that systemd gonna be Google Play Services of Linux at some point. I beg history to prove me wrong. For anyone interested, please look at Hardware attestation and TiVoization, thanks.

This is a bizarre comment for an open source init system

The history of TiVoization[0] tells us otherwise.

[0]: https://en.wikipedia.org/wiki/Tivoization

Re: What happened to running what you wanted on your own machine?

#93

Earlier quoted context omitted.

Roms face a different problem: bootloader locking. But the more Android changes drastically, the harder it is to integrate the AOSP changes into the different open projects

> Roms face a different problem: bootloader locking. Is that a problem these days? It was over a decade ago that I last needed to jailbreak a phone, nowadays it’s just "I’d like to unlock" "Ok".

That’s possible on very few phones these days. Only a handful of OEMs still ship phones that can be bootloader unlocked at all (at least in the US), and even several of THOSE require phoning home to the OEM to get an IMEI-dependent unlock key to pass to fastboot.

Source: 7 years of running deGoogled Android phones and 11 years of running ROM’d Android phones before recently moving to iOS and giving up.

Re: What happened to running what you wanted on your own machine?

#94

Earlier quoted context omitted.

Won't matter. Remote hardware attestation means they will know you're trying to bypass their control. You'll be denied service at every turn. Can't even log into your bank account.

IMO, I don't see how remote hardware attestation avoids being spoofed. Yes, TPM is involved, but the end of the day, it's an API request/response. There are so many ways the request could be spoofed, and the attestation likely requires coordination with hardware vendors that have proven to be Highly Secure TM with the history of secure boot leaks.

> I don't see how remote hardware attestation avoids being spoofed

Hardware cryptoprocessor. Keys are held in a tamper resistant secure element. You're not gonna get at those keys without pouring some serious resources into the task.

The keys are owned by the corporation and used to establish a root of trust from boot. If you change anything at all to suit your interests, verification fails, your machine is identified as "tampered with" and designated as untrusted.

Re: What happened to running what you wanted on your own machine?

#95

Executive Summary: run Linux

Won't matter. Remote hardware attestation means they will know you're trying to bypass their control. You'll be denied service at every turn. Can't even log into your bank account.

If you have the right to run what you want on your machine, then they do too.

So then the problem gets moved up to why are you (or group of you) not powerful enough to negotiate being able to run what you want and either not need “them” or be important enough that “they” need you.

And the answer will come down to the fact that 90% of people don’t care about running whatever they want on their machine, and they want the cheapest, quickest, easiest solution.

Re: What happened to running what you wanted on your own machine?

#96

What happened was people ended up putting a lot of money and sensitive data on their computers and desired a system which wouldn’t expose that just because they ran the wrong software.

This is the real answer that is rather banal and boring compared to conspiracies of nefarious money harvesting.

95% of people don't know what "Run your own software" means, because to them, the app store lets them chose what apps to install. And they don't get viruses and malware like their 2008 laptop did.

That being said, there absolutely needs to be a mechanism for "lowering the gates" if the user wants full control of the device they own.

Re: What happened to running what you wanted on your own machine?

#97
post #78
post #4

I was there, 3000 years ago, when we started ringing the bell about “trusted computing”. Honestly it’s not as bad as I expected

Trusted computing is just another name for vendor lock-in. It was never about security.

A more generous explanation is that it might be both — vendor lock-in also happens to be a security measure.

Having important info on your device and having that device accessible to the wild, wild, internet is a very real problem. If the "walled garden" is a flawed solution we should work on a better one.

Re: What happened to running what you wanted on your own machine?

#98

Earlier quoted context omitted.

> Then get a law passed. Today. Ha! Let me know how to achieve that and I will. I’ve advocated, donated, and volunteered for years on behalf of a number of causes, some with excellent organizations promoting them, and yet things continue to get worse. The only minor victories have been temporary delays of bad policy. No, the best response for the average citizen is stubborn noncompliance and constant passive resistan…

You can’t pass a law; because you have almost no bad examples to point to. Emulators, something that happened on the other side of the world, and piracy aren’t arguments. The banning of Parler did more for activism and awareness regarding platform control than all FOSDEM. Of course, HN happily piled on in favor of this decision, missing the moment to build common ground on platform control, for the sake of political…

It may be across an ocean, but Europe isn’t exactly the other side of the world geographically or culturally. Many of the ideas being trialed there are working their way into parts of the US. The frog is being boiled slowly, but the heat is rising more quickly in big cities.

> HN happily piled on in favor of this decision

HN is not a monolith with a single opinion. The loudest users at the time (not just here, all over the internet) were pro-censorship political activists, so maybe that caused you to interpret things that way.

> If the government, or tech, starts regulating out things people actually care about, then you’ll have your sway.

The public will not respond until the groundwork has been laid to make effective protest impossible. Only then will important things be regulated out. Until then it will just be “nerd stuff”.

Re: What happened to running what you wanted on your own machine?

#99
I hate to be the old guy yelling at the clouds, but was an LLM used to write parts of this?

> Apple sold the walled garden as a feature. It wasn’t ashamed or hiding the fact—it was proud of it... The iPhone’s locked-down nature wasn’t a restriction; it was a selling point.

Please, write as a human, I promise you it's good enough. I'd much rather read something that's a bit clunky but human written than something that's very polished but leaves me wondering what the author actually was trying to say.

Respect your reader, but most importantly, respect yourself as a writter too.

Re: What happened to running what you wanted on your own machine?

#100
post #42
post #24

Earlier quoted context omitted.

Mobile is where it’s bad. It never took hold fully on desktop since desktop is used for development and too many other things.

But the "walled garden" on mobile (iOS mostly, but now also Android) isn't really about trusted computing at all. Trusted computing (locked bootloaders) is but a small part of it. Trusted computing and even remote attestation have legitimate use cases. It's good, great even, that they exist. But just like everything, they can be used against you.

In fact most digital goods that are sold in large numbers via download, are, as far as I'm aware, sold with some form of DRM. Like films and video games. Otherwise piracy would be just too easy. MP3s don't have DRMs, and are still sold (e.g. by Amazon), but those now seem to be largely replaced by music subscription services.

And this might be a reaction to the fact that music piracy is quite easy; if it wasn't, perhaps there would be no Spotify where you get basically All The Music in existence for peanuts. (Note that no equivalent subscription service exists with regards to movies or games: Netflix and Xbox Game Pass have only a limited selection of content included in their subscription.)

Post reply on HN