| |
| ▲ | matheusmoreira a day ago | parent | next [-] | | > You can of course create an independent attestation database at any time Ah yes. They're totally going to trust my self-signed certificates. They're totally not going to restrict their trust set to the corporate owned and surveillance friendly Google and Apple devices. Come on now. > minimum security requirements for digital ID use Also known as "the user has no control over the device". Because users who have control can simply spoof this silly "digital ID" and there's nothing anyone can do about it. > We use that approach in several other industries. Your industries include the user of the device in their threat models. They want the device secured against the user. Absolutely unacceptable. | | |
| ▲ | izacus a day ago | parent [-] | | > Ah yes. They're totally going to trust my self-signed certificates. They're totally not going to restrict their trust set to the corporate owned and surveillance friendly Google and Apple devices. That sounds mostly like copium just to motivate your complete inaction. Again - independent, EU based, attestation database is completely possible to make and we're using similar approval processes across multiple industries to certify hardware - locally, here in EU. But yea, if you think you'll be able to print passport at home and then go travel and demand that government recognizes that as an ID document, you're a bit optimistic. | | |
| ▲ | matheusmoreira a day ago | parent [-] | | > we're using similar approval processes across multiple industries to certify hardware Why not tell us more about the requirements for hardware certification? Seriously doubt it's anything but the usual war on general purpose computing. Requirement #1, the computer runs the mandated surveillance software. Requirement #2, the computer does not allow the user to run any software not approved by the government. Requirement #3, the computer resists tampering so as to preserve the previous requirements. | | |
| ▲ | izacus a day ago | parent [-] | | > Why not tell us more about the requirements for hardware certification? Err, it's actually pretty simple: the token/certificate representing your ID (or credit card, or anything really) cannot be exfiltrated by userspace or installed kernel space apps or intercepted on the way to TPM when issued. And it cannot be duplicated. It's the same set of requirements that are put on credit card smart chips and biometric chips in EU IDs and Passports (which are essentially also TPMs). But sure, it's a all an evil conspiracy against general purpose computing. And they're all out to get ya. Now smash that downvote for a vote against the evil establishment. | | |
| ▲ | matheusmoreira a day ago | parent | next [-] | | > cannot be exfiltrated by userspace or installed kernel space apps or intercepted on the way to TPM So it must be secure against the user, as expected. Preventing the user from "tampering" with the token means carving out a section of the machine and putting it out of his reach. You just created a government embassy on the user's machine. There's no telling what it will be abused for, and there's no escape. > But sure, it's a all an evil conspiracy against general purpose computing. You just advocated for putting an inescapable persisent cryptographic government ID on everybody's computers. This is the literal implementation of the surveillance state. Everything you do online, this token gets sent. It's the end of anonymity. Not even Tor gets around this. | | |
| ▲ | izacus a day ago | parent [-] | | Yes, that's what a TPM or smart card chip in your ID/Passport does. Prevents tampering even by the "user". I have advocated nothing of the sort you're accusing me of. Please leave your strawman at home. Having a physical card fallback here is a necessity and nothing in these proposals shows that the physical card ID is going away. | | |
| ▲ | matheusmoreira a day ago | parent [-] | | > Having a physical card fallback here is a necessity and nothing in these proposals shows that the physical card ID is going away. It doesn't have to go away. Once the capability is there, they can and probably will simply make it mandatory to even so much as get an internet connection from your ISP. No unbreakable ID chip? No internet for you. The "fallback card" is exactly what added the necessary friction that prevented everything under the sun from demanding these sorts of verifications out of everybody alive. It was somewhat tolerable when it was just a financial transaction. It's still highly problematic given that AML/KYC laws are just the financial arm of global warrantless mass surveillance, but at least it was contained to the financial domain and it was possible to avoid credit cards and use cash instead. Putting this stuff in every computer kicks it up into 1984 territory by allowing tracking of anyone posting wrongthink online. | | |
| ▲ | izacus a day ago | parent [-] | | In most EU states you already need to provide ID to establish internet service, so what are you on about man? |
|
|
| |
| ▲ | imtringued 20 hours ago | parent | prev [-] | | >Err, it's actually pretty simple: the token/certificate representing your ID (or credit card, or anything really) cannot be exfiltrated by userspace or installed kernel space apps or intercepted on the way to TPM when issued. And it cannot be duplicated. So you need a proprietary browser running on a proprietary OS (both userspace and the kernel) with proprietary TPM hardware. You just proved the point. No more Linux. |
|
|
|
| |
| ▲ | imtringued 20 hours ago | parent | prev [-] | | >But.... that requires work beyond just complaining. So you have to build an entire parallel internet just because you want to use Linux? That's what your argument boils down to. The people who are complaining on HN are not platform operators, the platform operators don't care at all. To them it's not even about whether it requires work, they literally don't care. For the people who care, it's not a matter of work, because they don't operate the platform. |
|