The War on General Purpose Computing (2015) [video]
csclub.uwaterloo.ca
csclub.uwaterloo.ca
We (consumers) want to hold vendors accountable for policing "hate speech", kiddie porn, or terrorism, and various other centralized exercises of power that align with personal political whims. We want convenience and constant new features. We want things to work smoothly. We sorta care about security, as long as its not inconvenient. And we don't want to pay up front for any of it. Better still for it to be free with some ads.
Governments are legitimately concerned with terrorism, nation-state influence campaigns, industrial espionage, and law enforcement. They have to solve these problems, with constrained resources, in a technology environment that moves far faster than they can. They will push the regulation tools they have, as hard as they can, to solve these problems, if we let them.
There are almost zero short-term consumer/voter/elected-offical incentives for free, open, secure, interoperable systems. In fact consumer, political, and financial incentives are all aligned, currently, towards centralization of power and walled gardens. And the Silicon Valley model really is eating the world.
This is why open source has become so incredibly important. Open source hardware and networks doubly so.
There's still a large minority of us that sincerely don't.
Also if you run a platform that ends up being used to say live-stream mass murders, it seems pretty reasonable that you would want to ban that. Ultimately companies are run by people. No one wants to work for a company that becomes a platform for that kind of horror.
Not to diminish the issue, but this is mostly an American problem as far as I see it. I realise these are also American companies, but conflating the entire world to be in danger is a bit disingenuous imo.
MANY European countries (speaking from a Scandinavian perspective) don’t suffer from this, and while there’s a danger of American policies trickling down, that has been severely diminished in the past decade as there’s a movement of all of us (that I’ve seen) sort of re-evaluating our admiration of the US that was built in the 90’s - 00’s.
From the outside this isn’t a direction the world seems to be moving in. Just more crazy US spiralling.
Not the smartest choice to make yourself identifiable, but such legislative blunders still need to be corrected.
I don't believe a house search is some trivial policing. I think the state failed again to protect reasonable rights. And yes, the hate speech legislation of Germany should be adapted to the 21st century. This won't happen politically, because society currently loves pointing fingers at small missteps. A wrong joke and you get a shit storm.
It is the usual suspects, you hate women or are a racist are the most common accusation. People really start forgetting what these qualifiers really mean. And I believe they get far too much political support and that this isn't a healthy development.
https://www.usnews.com/news/best-countries/articles/2021-02-...
I agree that people have more and more sources triggering their fears and prejudices for a buck, which is making them angrier and angrier.
So why doesn't that matter? Because the "employed" are not gainfully employed. They work longer hours for less wages. Longer hours because the competition pool is larger, and less wages for the same reason PLUS inflation.
The average joe may not understand this. But he certainly understands that he can't take vacations, he can't get sick, his electric, gas, and food bills have all doubled or even tripled (in some regions). Despite working, objectively, harder than ever he seems to only get further behind. This makes Joe angry. When Joe can no longer blame the government either due to perceived incompetence or manipulation by think tanks, he is soon to blame his neighbor.
This is the secret of the majority of "extremism" that makes the news. They will certainly sell it as racism, or sexism, or fascism though.
Having a job that doesn't pay enough to afford to pay rent & utilities, buy food, pay off college loans. I could go on. Just saying unemployment is low doesn't capture the nature of the working poor. Barbara Ehrenreich's book Nickel and Dimed covers this well. People who work in software and make six figures tend not to be squeezed to afford the basics, except perhaps if they have to live in one of the highest COL cities in the US, but there are millions in the developed world that hold 2-3 jobs and still barely afford living.
Unemployment is at an all-time low? That's great, but people are working their backsides off and cannot afford to eat or heat their homes.
In the UK we have had twelve years of the right-wing extremist Conservative government and their "economic austerity" to "right the ship". What this has meant in practical terms is that wages have not risen in twelve years, taxes have gone up and up and up, and public spending has gone down and down and down. We had the woefully inept Kwasi Kwarteng who blew £60 billion off the UK's economy by raising taxes on the poorest and cutting them for the richest, collapsing most people's private pension pots. We went from roughly 40,000 people in the UK using food banks in 2010 when the Tories took power to 2.5 million people using food banks in 2022 - and these are not just "poor people" who the tabloid trash papers sneer at "well somehow they can afford mobile phones and TVs, why can't they afford food" - no, there are people on £30-£40k per year, who simply cannot afford to feed their families because they have to choose whether they keep the lights on, buy food, or pay their mortgage.
The political right have over the past 20 years done incalculable damage to the world.
Thus, traditional parties represent the interest of some subset of the established elites. Which means that the current socioeconomic arrangement is broadly in their advantage. They know that those problems are real, but they can be only solved by giving up some part of the pie. And organizations are much more selfish than individuals, so they never give up unless they believe that the alternative is to lose even more (hence why a messy revolution somewhere else can often do wonders).
we've just pissed away 700 billion on measures that most of the population banged pans on Thursday for.
my sympathy is running out.
There's certainly a rise in talking about stuff being "extremist", but how much of this is genuine?
The incentives (more outrage, more views, more clicks, more ads) don't exactly encourage honest reporting or even discussion on this.
Fully in agreement extremism is on the rise and the internet aids this.
https://www.nytimes.com/2018/11/06/technology/myanmar-facebo...
https://www.cnn.com/2021/10/25/business/ethiopia-violence-fa...
That was Facebook, not Twitter, but this is not just a problem for America.
Probably because Twitter has already demonstrated an ability and desire to curate what people see in their feeds (all in the name of increasing engagement and pleasing their advertisers). So, naturally, people see this, and tell Twitter that if they're going to interfere to the degree they already are, then they must also help ensure the safety of their users, and deal with bad actors directly. In a way, this is Twitter's own fault.
No one expects that Sharpie even has the ability to police the use of their markers, let alone the desire or resources to do so. Most people don't want the USPS reading their mail (and it's a federal crime to do so!). I think the Verizon example is where we're starting to get in a grey area, with telcos getting pushed to implement tools and protocols so people can verify calls are legitimate. That's more about the spam/scam problems with the phone system, not about stopping bullies, but it's a bit closer to that. A further issue is that most people hate phone calls, but love posting stuff online, so naturally they're going to focus on the thing they actually willingly spend their time doing.
I think a further issue is that most people can't really opt out of USPS or the phone system, realistically. But if Twitter passes some threshold of toxicity for them, they'll just stop using it. Twitter (the company) doesn't want that, obviously, so it's in their interest police their platform.
People still don't blame Sharpie or USPS or Verizon. People have tried to blame WhatsApp, it doesn't stick because WhatsApp is private. The culture hasn't magically changed. Companies like Twitter know that when advertisers and users complain about hate speech, they're not just asking for Twitter to be held "responsible" or whatever that means, they're telling Twitter that they will leave.
The issue came when the news media decided that it was newsworthy that undesirables we're saying undesirable things on social media and blamed the platform as a whole. Now it's a pr issue for advertisers to be on the platform at all whether or not they are adjacent to undesirable content.
You're welcome to hold that opinion for closed 1-1 messaging platforms that don't have amplification features, but it's just plain wrong to assume that any platform that can amplify ones voice into the unwilling or ignorant and somehow be immune to this level of scrutiny. It's a farce and will certainly never end well for those that try.
Edit: I also think no discussion of censorship/moderation is meaningful without addressing the cannon of falsehood and stochastic terrorism. Those are massive, very real problems that must be addressed.
I think that Twitter or other social media may have tiered censorship based the number of followers to limit it to be the appropriate human-scale of influence
We need to exam these issues in the context of social impact.
Public airwaves (TV, radio) have have fines for breaking various rules even when it’s a member of the public speaking live. Thus the classic tape delay and bleeps on all life content.
Further back Newspapers, advertising, and letters to the editor etc where limited for so long that it was a constitutional issue in 1776.
So having platforms is hardly a new thing. We have been debating such freedoms for so long it’s part of various countries cultural identity.
The mid-20th century USA ended up developing extensive case law about the phone system. Once upon a time, quite a few people did think it was the phone company's responsibility to prevent such calls, within reason. And they litigated the question.
Does the phone company have the right to disconnect abusive and profane callers? Does the phone company have an obligation to disconnect such users? If the phone company fails to do so, are they civilly liable? Given the government-regulated quasi-monopoly status of the Bell system, was there a First Amendment or due process angle, if the phone company disconnects users for placing obscene or offensive calls?
The answers to such questions were not particularly obvious and it just sort of evolved organically to the status quo today. New laws were passed to deal with the situation, such as one that makes it a federal offence to knowingly place an obscene and unwanted phone call. And there are a number of regulations that impose an obligation on the carriers to try to reduce spam, unwanted solicitation, maintain calling logs, etc.
I can imagine that "problems with your Apple ID/Apple Card" scams are more convincing if they appear to come from an Apple number. I figured it was a scam but I called Apple up anyway to confirm.
I don't think Twitter gives a shit on what people think, but if advertisers complain then Twitter/YouTube will make sure to be very careful with what is allowed. I am not convinced by the arguments this advertisers have about not appearing on some "legal but bad" content" but is their money so they have the right to ask on what kind of content the stuff should appear.
You are correct if we treat social media companies as content curators. If we treat them as speech platforms you are wrong.
Regardless of your belief a "speech platform" (email, etc) can and honestly should allow these things in the spirit of actual free speech. If it is a content curator, then yes, one can infer that by curating so-called hate speech they are indirectly promoting it.
This difference is lost on people. Personally, with the amount of censorship and ads I am fine treating social media companies as curators and treating them appropriately. There are billions currently flowing into congress to stop this. Primarily from those social media companies that want to censor but still be called a "speech platform".
People often conflate their feelings with law. There is no law stopping you from going into a park with a megaphone and spewing what some people may consider hate speech. Consider even how vague the term "hate speech" even is. If I "believe" in two biological genders this, according to some, is the same as denying the holocaust. To some, criticizing the effect asylum seekers from certain countries has had on my country is consider not only racism but "hate speech". We have to be extremely careful what we consider "hate speech". Because the current definition of "hate speech", "disinformation", "misinformation", etc all center around one idea: "things I don't like should be banned, and things I do like should be promoted". This is party-neutral. Both sides of the coin want the other side to be considered hate speech mongers.
“You’ll take down CSAM but not spam/incitement to violence/revenge porn!?”
Further, user reporting as your only form of detection doesn’t scale well or protect your reputation.
To be clear they were not accused to of being anti-social. People who don't want gun manufacturers sued for what is done with their guns were called child killers, "sandy hook hoaxers", etc. The Bloomberg (yes, it was Bloomberg) money machine paired with the noise machine that is Mom's Demand Action has absolutely dominated the narrative around this.
But I think the real reason gun manufacturers are getting targeted is because the people who have been victims of gun violence see no other recourse. Gun control in the US is mostly laughable, and it's politically difficult (if not impossible) to fix these sorts of problems. So the next natural step is to probe the system to see if there are any creative ways to change things. Targeting gun manufacturers with lawsuits is one of those possibilities.
That’s without getting into the issue of allowing that type of stuff to continue to exist on platforms if the ideal scenario is for Meta/Twitter/etc. To just not police their platforms at all.
Or we could just say people on the internet are assholes and you need thicker skin. Would you be okay with government ID required to sign up to any website? If so, I can see why you have a vengeance complex.
We're talking about holding people accountable for child porn, and inciting terrorism. What the actual fuck are you talking about "need a thicker skin"?
Free speech absolutism is poison for actual freedom.
[1]: https://en.wikipedia.org/wiki/Lone_wolf_attack#Stochastic_te...
Such a service would make plain a simple truth we don't want to acknowledge: screens hold powerful sway over people, and algorithms hold sway over screens. That power (mood manipulation) can be used for good or evil. Maybe if people are given control over their own tools in this way, they can better appreciate the control that is exerted on them by others, and so better resist it.
I guess we will shortly see AI empowered moderation, where AI analyses text and gives it a hate score. I would prefer platforms that make no content suggestion at all.
https://www.youtube.com/watch?v=4Z2uzEM0ugY
Note that assault (which could be words, threats to life for example) is already against the law, it's psychological warfare to make up a new term "speech I don't like" and parade it around (write long wiki articles, mfg consent etc) like it has meaning. It's a term in the same class as "conspiracy theory" and designed by the same class of social engineering experts.
There'll be bluster, but it won't lead anywhere.
The people are now online and the people want this.
I did. Because I've been running discussion forums on and off for 40 years. If you let them, a tiny tiny number of foul people will take over your site by driving away all the normal people who don't want to be exposed to that garbage. Free speech absolutists have trouble understanding that such bad faith actors exist, and in sufficient quantity to crush what could otherwise by a robust, diverse discussion.
Build up some case law about what is and isn’t so it’s applied uniformly and take stronger measures against repeat offenders.
On other, less-enlightened forums, this would earn you a .jpg of a dog cocking its head to the side quizzically.
This will end up with masses flagging the current not popular thing. This is precisely why you need laws that ensure freedom of expression, self-determination and other human rights.
HN’s flagging system is more aggressive than what I want with less oversight. If you feel like you have freedom of expression here then surely HN but with a looser grip ought to be even more, ya?
We had content manipulation for political purposes. There is no guarantee that this will stop now, but changes were certainly needed. It isn't too great that it is now in the hands of Musk perhaps, but he at leaset has a different goal. Even if that is just a pretense it would still be an improvement. And no, some alleged bots are no excuse to just editorialize topics.
This inhibits people forming their own opinion if they will be fed with preapproved messages. So yes, it was a severe problem. Even European leaders called out Twitter when they banned Trump. And it was certainly not because they liked him.
I do believe that flagging is abused on HN from time to time. It just doesn't happen too often and HN isn't too relevant for public discourse. Twitter sadly is since a large part of journalism is about the latest Tweets people can be enraged about. Overall HN is tolerant of diverging opinions as far as I have seen.
Yes, in 2022. I have ad fatigue. PTSD, even, from the onslaught and effort to avoid them.
But I recall a time when I enjoyed ads and actually looked forward to them and paid good money for magazines, and to a lesser degree TV, full of ads that somehow seemed informative and civilized and entertaining. Byte Magazine, The Computer Shopper (all ads! yet I paid for it!), Car & Driver, Popular Mechanics, Bicycling, you name it. I don't think this is nostalgia; I was informed and entertained. Never again, I suppose...
Look at Dollar Shave Club. A tiny little company that was able to get to an insane valuation chipping away at the consumer mega corps because of targeted advertising and some good ads. I've heard that small consumer packaged goods vendors are having a tough time now that Facebook got their tracking shut down. The only people who can effectively market mass market stuff like that now are the megacorps like Unilever and Proctor and Gamble who can do multi-million dollar poorly targeted campaigns.
It would be nice, I think, if people who are shown ads could add tags to the adds for the type of product/service the ad is for, or other aspects of the ad (e.g. “this ad is horny”), and indicate classes of ads which they claim they would not be interested in, which, hopefully, advertisers would prefer to show ads for their products to people who would be potentially receptive.
For example, I do not watch horror movies, and I don’t think this will ever change. I find video ads for horror movies a little stressful (not like, in a way that is an actual problem for me, just unpleasant), and I think it would be to the advertiser’s benefit and my own for their ads to be shown to someone else instead of me.
Similarly with ads for fashion, or at the very least for women’s fashion. I can imagine the possibility that there could be some kind of clothing item where I’d be interested in buying due to an ad, though probably not anything advertised using the word “fashion”.
If ads are supposed to have the benefit of introducing potential consumers to goods/services that they might be interested in buying, why don’t they allow users to provide more information about what they aren’t interested in? It seems like it would be beneficial to all parties.
This exists already (at least to some extent): https://support.google.com/My-Ad-Center-Help/answer/12155451...
The other section about interests and brands, uh, well they seem to just not work for me? Like it keeps saying “we will populate this section once you’ve been shown more brands/ads”. I don’t have an ad blocker installed. This is both on my phone and on my laptop, and is the case for all my google accounts?
I know it at least used to have an “interests” section that I could update, but that didn’t really solve my problem either.
The reason I specified a viewer-tagged system is because it would, I would think, avoid the problem of [the categories that one can mark oneself as dis/interested in] being largely useless?
Autres temps, autres moeurs. We live in a culture today where if you are not active in the fight against X, then you condone X, ipso facto. Back in the day, companies could legitimately claim that they were in the business of delivering a product, and others had the responsibility of policing against social ills. In today's era of corporate responsibility and ESG, that is no longer the case. Open source will be affected too, as open source cannot be sustained in a vacuum; it needs institutions, foundations, and corporate backers, all of which will be pressured to comply with "ethical source" guidelines.
Open source is nowhere near as important as the right and ability to read and modify. The most popular browser is (mostly) open-source, and so is the most widely-used operating system. The megacorps are really happy to advertise the fact that they're contributing to and using OSS. Yet the situation is such that while you can see the source, it doesn't necessarily mean you have any power to do anything other than read it. What good is having the source if you're prevented from actually using it, due to various "security" features?
Contrast that with the rise of the PC in the 80s and 90s through the early 2000s and the slowly-dying culture that came with it. The majority of software was closed source, but it didn't stop people with a disassembler and a hex editor from analysing and modifying it.
Thus I think focusing on OSS is merely a distraction.
It's that power has shifted to centralized clouds and nobody has stepped up to make self-hosting as turnkey as open source is.
We need an open source movement and ethos for DIY cloud hosting, if not shared resource fabrics.
Consumers don't want vendors to police content, vendors want to be a hub of content and policing content is the only way they can appease the diverse group of people they want to continue to grow. Consumers are perfectly happy to self-police content, the problem is that the models that allow for that make it a lot harder to discover content.
With your comment of incentives I think youre placing the blame wrong again. The reason there's no incentives to create free, open, secure, interoperable systems is becausese capitalism places importance on prior ownership. There's a lot more money in being the standard that everyone has to pay a royalty to in the future than there is in giving out the standard for free and just being a user of it(see: meta and the metaverse).
And after the party you don't like is elected, they will use that same power you gave them for going after say... women who underwent abortions. Be careful what you wish for.
Religiosity.
The past is not shackles on the future.
I was musing to a friend the other day (in context of AI actually, not general access to computing) that Marx apparently missed a fork in the road in his linear idea of 'historic necessity' regarding the deterministic nature of social system transitions. Since technology, now cognitive technology, is such a huge amplifier of wealth, it now seems the Capitalist class can chart a way in the future that decouples from labor and assumes control over advanced technology. This path of the fork in the road will not end in a workers paradise ..
So all we need now are the missing tracks of this train (and all the charming must-see stops along the way).
I am sure many people here have seen this, looks to me this is the direction society is slowly heading towards:
www.gnu.org/philosophy/right-to-read.en.html
It's called Pluton, and (scarily) there is not much public technical information about it.
I think that ended up as some sort of trusted computing project; we were worried back then that linux was gonna be impossible to run in our PCs... well then PCs turned into smart-phones and even though they run linux (or iOS), we ain't choosing what they run
the name was something with a P? like palladium or something that has no P but sounds somewhat like that?... I'm saying I don't remember.
There's a nice quotation from the end of the How-To Geek article:
> As long as these measures don’t prevent us from running software we actually want to use, Pluton is a welcome development.
Indeed, Pluton could be beneficial, assuming you are on the side of fully trusting the Microsoft ecosystem front-to-back. Or scary if you don't trust the old 'Softy.
That being said, Apple's M1 architecture has a similar security chip installed as well. Some people legitimately want these walled gardens. We here at HN are probably more on the fringe side than the majority.
I think the rebels have to do better, to wit, they (we?) have to work smarter to make software that's just as functional but with far less code, so that it can be audited by an actual human being. Software engineers take a blase attitude about dependency bloat, but that must change. We also need to be ready to run on open hardware when it is released. Last but not least, we need to invent a way for the best hackers and geeks to sift through the software we run, people we trust to find flaws and exploits and not use them. I, for one, would gladly pay for this service, and I think thousands of others would, too.
What little there is, and even articles that are occasionally posted here about the dystopia it'll bring, seem to have vanished and/or be taken over by corporate mouthpieces spreading FUD in the comments. I can only see that as being the industry trying very, very hard to stop any dissent.
It's not, notice how easily it was circumvented in the story. In reality, it would not be possible to lend Lissa the computer with books, because there would be continuous FaceID checking who is the real person staring at the screen.
Also, in the story, "ten percent of those fees went to the researchers who wrote the papers", that would be a great upgrade for the current world.
In my experience the general public's notion of "general purpose computing" is "Well, my phone can do everything I need, isn't that general purpose computing?"
Is something that's being said only in advertisements, or by people conditioned by modern mass market tech to feel helpless, and define their needs as subset of what they know how to do on their device. In my meatspace circles, the people who say "oh my phone does everything that I need" tend to regularly ask me to help them with stuff they need, but their phone (or their knowledge of it) is, in fact, insufficient for.
The war is there, but it seems not all is lost just yet.
There are defensible arguments for secure boot, but they all thoroughly miss the larger picture in my opinion.
That said, I do believe that Windows will loose some endusers finally. Not the masses perhaps, but as long as there is an alternative, I am happy. If some apps forces me to use a specific machine or OS, I will not use it.
The components you are referring to confer a clear and important benefit to devices – a secure boot chain. This is the most foolproof way we know to prevent tampering or hacking a device.
The problem is that some of these secure boot chains don’t allow being overridden by users. Many do – the Pixel series of phones, the M-series of Apple laptops, and Windows S devices all allow “turning off” or “hijacking” their secure boot chains. The further problem if you can turn off secure boot is that these pieces of hardware often can’t then be turned back on with a different secure boot chain – say, one based on open source software. Debian and NixOS and other OSes already have zero-trust ways of verifying the integrity of their software using reproducible builds, but they can’t go the step further and have the hardware it is installed on do the same verification with some sort of signature.
GrapheneOS has figured out how to do this, and it leverages the secure boot chain of the Pixel device. It is very cool and I think a nice symbiosis between the hardware and open source software: https://grapheneos.org/build#generating-release-signing-keys
The next and more problematic part of what these technologies provide is integrity, which is the guarantee that on top of the boot being secure, the software being run is from the manufacturer and it behaves as the manufacturer intends. A lot of functionality currently relies on this guarantee of integrity: anti-cheat software, DRM software (Widevine, HDCP), transit cards, credit cards, driver’s licenses, etc. The technology manufacturers aren’t building this software because they want to, but because they have to. The Original Sin for the iPhone was carriers: at the time in 2008 they were really worried about unlocking and tethering, and the prank of the day was to put a flashlight app into the App Store that allowed tethering via a proxy. Rights holders, carriers, game manufacturers, etc all pressure tech companies to use integrity to solve their problems.
Many of these solutions have alternatives that don’t require OS integrity: if the government issues signed digital IDs, for example, then it wouldn’t matter what software is running on the phone. Some are tough and don’t have alternatives, like anti-cheat and DRM. DRM in particular is a complex US legal issue: anti-circumvention is straight up breaking the law. No solution would be comprehensive without changing the law.
Progress has been made, though! The fact that we have figured out ways of unlocking boot chains in a way that is acceptable to all of the large companies is awesome. Apple does it by being able to guarantee other secure boot chains on the device remain intact, and Google does it by ensuring the device is wiped. This took real engineering effort to do.
It’s important to push these companies to go further. An M1 iPad is almost identical to an M1 MacBook in hardware, and yet Apple only allows the latter to run Linux.
The comment is already a blog post, but another big problem is that these tools are great for anti-competitive purposes… which the government is increasingly taking a look at.
Why? Because we let it happen. We keep buying these things that have this function as a feature. The answer is simple but it demands dedication and resilience.
Simply stop buying them and using them. Yes, a boycott. There is no other answer because they are making ton of money doing things this way and the one;y way they will stop is if we stop making it profitable for them.
At some point, it's like telling people who don't want to drink dirty water that they should boycott their one and only water provider.
Maybe there would've been a chance if it was easy to prove that for every TPM chip they have to manufacture, they need to kill a small kitten. Or, if computing hardware was a commodity like a laundry detergent, so you could just choose an alternative that has near-identical specs, near-identical design and near-identical price, but comes without that one feature you don't want.
The companies don't care what you think, because this is a supplier-driven market. As a consumer, you can only choose out of what's available on the market. There's only so many players; barriers to entry are high, and they corrupt those who scale them[0]. They're going to keep making money and keep telling you what to buy, because they know you have no other choice.
----
[0] - You need a lot of up-front capital to start a hardware or software business. You're not going to pay for it out of your own pocket. The kind of people that will happily lend you money? They're the ones that will make sure your product fucks end-users over in every way possible, because they want to maximize returns on their investment. So even if you started wanting to do good, you're unlikely to be still doing it if you succeed.
It represents a black-and-white way of thinking about the problem when the entire point I am trying to make is that everything is gray and if you work in technology you need to understand the different shades of gray better.
Is your statement meant to be inclusive of, say, all laptops? I was under the impression that one can setup a machine to boot using personal keys rather than Microsoft keys: https://www.dannyvanheumen.nl/post/secure-boot-in-fedora/
The process of being able to use your own keys is certainly cool, but it is less impressive if anyone with physical access to the machine can also do that
Smartphone OSes have propogated their own curated walled-garden app stores, and then the desktop OS vendors follow suit. Soon it will simply not be possible to install unsigned, uncertified software on your computer, and that will be the end of GPC.
Microsoft Windows has had that for a while. It's called "Windows S".[1] Only software from the Microsoft store can be installed.
The lowest price laptops from Walmart run Windows S.
[1] https://support.microsoft.com/en-us/windows/windows-10-and-w...
https://support.microsoft.com/en-us/windows/switching-out-of...
Sometimes. For now. Machines in enterprise and school environments often have that option locked out.
I cannot fathom how Americans can point at the EU successfully forcing phone manufacturers to switch from 40 different types of proprietary chargers (we used to have different chargers for different models within a phone series ffs) to 1 and say “wow fuck the EU for taking away the freedom that obligated me to have a dedicated charging drawer”. That is the true mental gymnastics.
Same with privacy. What sane human thinks “yes please, farm, process and store into perpetuity all the intimate data points of my life”..
I'm mostly concerned about it locking out the development of new standards that aren't USB, even if that was an unlikely development anyway.
That's because, not in spite of the measures taken by the EU, which happened quite a long time ago.
We're talking about things like banking. Yes, some of this already affects services that are needed in practical sense to function in modern society, and it'll affect more of them over time.
> or create them [services that respect freedom]
Impossible, because the market is highly competitive, so services respecting freedom have no chance to survive for long, which also means almost no one is willing to try making them - and more importantly - funding them.
> or find alternative ways to meet the same need.
Increasingly close to impossible in a practical sense. Observe how many things are increasingly becoming mobile-first or mobile-only.
Banks, again, are a litmus test: there are plenty of new ones that don't have a web interface or physical presence, and the more traditional ones all strongly push users towards being dependent on the phone app (even if used only as an auth tool, it's still a hard dependency), which of course will happily use hardware and remote attestation to ensure you're not using a device that isn't a pristine, unmodded version of what the corporate world wants you to use.
The things you mention off the top of your head are just some of possibly 50 or 60 pressing issues relating to "consumer rights", trade and manufacture, intellectual property, information rights and privacy, digital sustainability, security and resilience.
The time has come to collect them all into a coherent analysis and set out limits, principles and safeguards.
Those most interested/invested in this will not be random Joe in the street (about whom most readers here will proclaim: "they don't care and therefore deserve no protection") - but developers. Us. Because without some guidance to protect our industry from ourselves it will spiral down over the next decade until "technology" becomes the second common rallying point, after environment, against which people organise.
Like climate, I think we are at a potential turning point, with a window of opportunity, to decide whether digital technology will be part of the solution, or another part of the problem.
But, in all sincerity, do you really think that the readers of HN would positively discuss a "Bill of Bytes"? So far I have found the pervading cynicism and stuckness to be discouraging. It's very different when you are in a room, face-to-face with people who are themselves exasperated with digital technology and open to creative thinking about how to fix it. But on the internet, everyone is their own urbane expert, "too cool to care". Or, increasingly, they're an AI troll-bot cleverly designed to derail any reflective exchanges.
Working on a personal level is more where I'm at. Every year another of my classes pass out into the world, get jobs in cybersecurity or development. I hope they take the deeper lessons with them, and try to make the world a better place for everyone who uses technology.
Meanwhile writers like Cory Doctorow are doing a great job of bringing issues to non-technical readers
I think there will definitely be an interesting discussion. But that's only the tip of the iceberg, and the more important discussion is to be had with a larger cross-section of society -- like in those classes and books.
I believe it is important for us (technologists, power users, etc) to do the ground work and prepare a forward-looking framework for when the time is ripe (just like remote work/interaction technology languished for years before Covid suddenly drove up adoption).
It is a topic I care about deeply (and have been toying with the idea of a curriculum to "compute better"). I would love to engage further on this (offline) if you're interested.
Thanks for the pointers; I'll definitely look up the books :-)
Doesn't this require a change in copyright law? As far as I know, ripping a CD for personal use is still technically an unauthorized copy in the USA.
Making a backup copy of a CD for yourself is legal as long as you don’t distribute it to other people. It falls under “Fair Use”. https://legalbeagle.com/12719622-dmca-backup-of-copyrighted-...
Law/Policy/Liability and whatever other methods one can get skin in the game are the only answer. Harmful software has to be punished.
Remember this, when anyone brings up mindless arguments against encryption or promotes other policies eroding the internet.
The internet is invaluable to modern society, in the same way that the wheel is... politicians don't fuck with wheels, even though they are invaluable tools for criminals and terrorists, no one would be stupid enough to risk breaking wheels. Politicians need to wake up and realise that the internet is not a toy.
And, of course, the TECH will be bullshit, but the laws will be changed to support it, and it'll make wheels less useful for people while not affecting terrorists at all, but hey, you should be happy your wheel subscription comes with so many colors this season! And have some patriotic pride, after all, our wheels-as-a-service companies account for a third of our GDP!
Case in point: DRM.
Lockdown: The coming war on general-purpose computing (2012) - https://news.ycombinator.com/item?id=32224751 - July 2022 (87 comments)
We will win the war for general-purpose computing - https://news.ycombinator.com/item?id=27859463 - July 2021 (178 comments)
Taking a Stand in the War on General-Purpose Computing - https://news.ycombinator.com/item?id=26242991 - Feb 2021 (287 comments)
The Coming Civil War over General Purpose Computing (2012) - https://news.ycombinator.com/item?id=24866279 - Oct 2020 (210 comments)
Lockdown: The coming war on general-purpose computing (2011) - https://news.ycombinator.com/item?id=19872364 - May 2019 (59 comments)
Lockdown – The coming war on general-purpose computing (2012) - https://news.ycombinator.com/item?id=14335261 - May 2017 (96 comments)
The coming civil war over general purpose computing - https://news.ycombinator.com/item?id=4436139 - Aug 2012 (98 comments)
Lockdown - The coming war on general-purpose computing - https://news.ycombinator.com/item?id=3448754 - Jan 2012 (46 comments)
The version linked here seems to be more about collected examples of such war, DRM, right to repair etc.
Perhaps more importantly, they just don’t want to.
People want appliances like smartphones. That’s it.
The more computers there are the more dangerous bad actors becomes and the higher the cost of negligence. Botnets, DDOS attacks, etc. the only real way to combat these is at the source and that’s by taking away management of those devices from most users.
Then you go on to assert that authoritarian control is the only viable option. Here we have counter examples! Systems like Pop!_OS are parallel efforts to desktop systems like mac or windows, not designed for masterful smart supernerds but just to ne viable desktops for all, without fiddling, with safe-enough defaults. It didnt take suborning users under corporate whip to get here. Windows & Mac also show general purpose computing is in the broad possible- would that phones have at least this much freedom. But they dont.
I'm reminded also of our car-dominated cities in the US. In our current built environment, cycling isn't considered as an option by most because it doesn't feel safe. But cities around the world have shown that if you change the infrastructure such that it does, people will start cycling. The high car usage isn't a revealed preference, it's the result of a lack of other options.
So too with tech. The only options typically available for smartphones are Android with Play Services and iOS, and while it's possible to have Android without Play Services, you won't find phones sold that way unless you're technical enough to know what to look for, in which case you can probably install it yourself. (And things break in weird and wonderful ways without Play Services, because much of what we now consider core functionality for a phone has been moved into it.) Effectively, for the typical user, it's not an option.
Likewise with Linux desktops; they're more available than the phones mentioned above, but they're still not likely to be found where people typically buy laptops and desktops. You have to specifically go seeking them out, meaning the typical shopper doesn't even see them as an option.
Even on mobile, you have locked down iOS vs open Android and what do consumers choose? Android used to be incredibly open and was badly losing to iOS (outside consumers who just couldn't afford it) as it was open to viruses and fragmentation. Google has since learned from that mistake.
But there's always some other excuse. It's like communism, it's just never been tried, all those tries don't count because some aspect of reality got in the way. So what will it be this time? You don't like Google? Linux too hard to maintain? Say all the reasons that you consider way more important than general purpose computing and you'll have proved their point: users just don't want to.
You know why companies put so much effort into locked down platforms? Because users pay them for it. Anyone, including you, is free to dump their effort into making general purpose computing great again, so why don't you do it? Say why you're not doing it back to yourself, it's the reason why no one else is.
I can't imagine any farmer not wanting the option of shutting off remote updates and remote access, and just having complete control over the equipment they bought. This is particularly true for older hardware... i.e. many old computers will run Linux just fine even if Windows support was ended years ago.
What farmers want means nothing if they don't pay for it. If there is some hidden wellspring of farmers who really want those options then any manufacturer who makes tractors with those options will easily steal lots of customers and profits from John Deere. That's what you might call a "lucrative profit opportunity".
But it won't happen, because farmers don't actually prioritize it when buying tractors, they prioritize tool efficiency and are content to idly complain about this issue without putting any money where their mouth is. Go ahead, start a root-access tractor business, then customers will suddenly tell you 99 reasons why John Deere's tractor is still better than yours because these telemetry options are some of the least important things when buying a tractor and practically no farmer will actually reward you for it.
But sure, they want it. They'll even go as far as writing an internet comment complaining about it!
Perhaps the same should apply to vendors.
I feel that here in he UK most people don't fear the government, they just think they are a bunch of useless muppets who have no idea what they are doing.
It is the tyrants favor to be seen as useless and weak.
No you can't. It's far more complex than that, you have to be a very bad person (or very VERY stupid repeatedly ignoring warnings) for that to happen.
> can't own firearms
Good! We don't want people to have them. (Only somewhere between 1-4% want weaker firearms regulations)
> You have barely avoided (for now) a backdoor being forcibly installed onto every chat and messaging service
True, and it was quite right for the intelligence services to lobby for that, that's their job. But our democratic system worked and it was prevented by the multiple levels of government. They will try again, but I trust the system will prevent it.
> you may still see required snooping on semi public platforms
And I wouldn't be surprised if there is general support for this in the UK.
That was enough for one old man to get arrested.
https://www.lancashire.police.uk/help-advice/stop-and-search...
> Personal Application Omnipresence, PAO. It's a theoretical computing model where your applications are available to you from any device.
> My ideal for computing consists of applications that run on a central application server that I own. I want each application to be a single running instance to which I can connect and then interact with, from anywhere, from any device.
edit: I don't mean this as an insult. I wouldn't want people to read "most users" and assume they aren't in that group.
Hardware is still totally not open, period. Try buying a PC with an open source BIOS or CPU, you can't!
https://support.system76.com/articles/open-firmware-systems/
The "open firmware" marketing term is a bit of a misnomer here as there is probably plenty of closed source firmware in those devices in various components, but at least the BIOS is open source.
See also: https://www.youtube.com/watch?v=HUEvRyemKSg
Try to buy a 802.11ax WiFi router that allows running open OS. Good luck with that!
I believe there are some technical root causes that must be addressed, as well as those political and other issues. Unfortunately, the non-technical problems highly discourage proper technical solutions to these issues. I'll enumerate them here anyway.
1 -It's practically impossible to secure the hardware. Even CPUs have embedded control systems that form "management" layers hidden from everyone. Nothing built on top of this traitorous layer can ever be safe. It's possible to build something completely open and reasonably secure, but the market discourages it.
2 - RAM is unacceptably bad, most systems lack ECC as well. If we had properly tested and validated RAM, RowHammer wouldn't work, ever.
3 - The Operating systems themselves are usually modeled on Unix/Linux in some fashion, where there is no capability based security[1]. We're using a security model that was fine for the relatively low threat environment of small network of computers all serving one employer. It's entirely unfit for purpose in 2022.
Note: If you assume I'm talking about "allow this app to access X", you really need to read the Wikipedia page.
So, with the current Tower of Babel that is the software world, everyone blaming everything but these root technical causes, because there are fortunes to be made selling what are effectively band-aids in the field of CyberSecurity.
I firmly believe it's possible to fix this, all the way up and down the stack, but I'm having doubts about my own ability to survive until that day happens.
> I firmly believe it's possible to fix this, all the way up and down the stack, but I'm having doubts about my own ability to survive until that day happens.
Did you consider Qubes OS, a security-oriented OS?
Could you give an example where the capability-based security would protect you from some threat, whereas Qubes OS wouldn't?
Unintended targets are simply not accessible from a wrong domain, i.e., by wrong programs.
What year is the article from? David Cameron resigned as British PM in June 2016 and as MP in September. He since seems to have held a number of positions on charity and corporation boards, I couldn't find anything that would tie him to current political decisions.
in the former case the current pattern of abusive oligopolies will persist as society continues being dazed and confused about the new toys and suspends critical judgement
but we might be erroneously projecting the rapid developments of past decades (and the idiosyncratic events and actors that shaped them) into a future that is increasingly driven by other dynamics
for one thing, the pace of innovation/adoption seems definitely to be slowing down facing a combination of technical and behavioral limits. a few more years without self-driving cars and regular space travel tourism and we might start having a second look at what has been the quid-pro-quo of all the tech hoopla. awareness of the dangers and pitfalls of surveillance capitalism (which is now the de-facto economic model through which computing is deployed) is diffusing, slowly but surely. finally, the ability of a tiny crowd of severely under-resourced hackers to maintain fully functional alternatives, whether that is the linux desktop, its huge collection of applications or the fediverse, shows to anybody that cares to look that there IS an alternative.
Once/if the TINA spell is broken revisiting the role of computing in society may get us into completely different directions and the suffocating status-quo may forever be a thing of the past
And a bunch of these predictions never materialized. Subscription models are more widespread, but there's also more and better choices for opting out, and a much richer variety of development targets and ecosystems to mess around in.
I didn't think it before, but I think it now: this is what kills general-purpose computing - subscriptions, and everything-as-a-Service in general. They make the actually important part of the offering gated and completely outside of your control. You're left holding an interface to a remote thing that can refuse to operate for any reason, including you trying to use a general-purpose computer to access it. This is not a hypothetical anymore.
> there's also more and better choices for opting out, and a much richer variety of development targets and ecosystems to mess around in.
Mess around in, yes. Use in practice? Not quite. I think the most clear and worrying trend is remote/hardware attestation on mobile, in combination with subscription model / SaaS as mentioned above. The litmus test here is banking apps[0]. Banking is very much critical to life in the modern world, and banks are strongly pushing for having a mobile app as hard dependency[1] - and those apps make use of remote/hardware attestation. Ostensibly it's for your own safety, but as a side effect, you lose control over your own device. The use of those attestation APIs is accelerating[2].
In short: yes, you have a "much richer variety of development targets and ecosystems to mess around in", but if you don't sign the right contracts and the platforms aren't properly locked down, "mess around" is all you're going to be able to do with it.
----
[0] - Though I suppose the first real warning was gaming. DRM on media or games alone wasn't considered as worrying, because you could always find alternative source. But anti-cheat measures on multiplayer games are the first well-known DRM applied to an activity whose entire value sits in the network that's out of your control, and therefore not substitutable. You can't torrent a CoD or DotA multiplayer match.
[1] - Even if you use the web interface for everything, which many banks don't provide, there's a push for using the app as the auth tool - if you do, then the app becomes a hard dependency for you anyway.
[2] - The APIs are increasingly easy to use, increasingly promoted (at least in the Android world), and increasingly hard to hack - from what I read as an outsider, they've completely gutted the custom ROM scene for Android, as whatever cosmetics/QoL improvements you gain are not worth the functionality loss.
I think that general purpose computing is simply changing.
It's not going to be "A man and his Linux in a basement" anymore but rather "Let's run some code in a remote distributed serverless runtime". Cloud Excell for the masses.
One part where we can already see this is how cloud environments like colab, hugging face, repl.it, etc remove some parts of maintaining a full installation of an OS. If you just want to write some python and run it on a GPU you don't have to buy a GPU, install drivers, etc anymore.
We should be happy that we won't have to care about the bare metal (unless we want to).
While most consumers don't really care and actually prefer the switch to everything being cloud-first, the stagnation it can cause for other developers is substantial.
E.g. If I want to make a cool email client, I don't have to ask the user's permission to send and receive emails, I have to have Google's permission to access their machine and to make this compelling as Gmail, I have to then store all of my user's data on my own servers. This compared to me just writing a client-side application that has no server requirements is a huge bust IMO.
My preferred future is where every user has their own server that can run general purpose applications. It would have all the benefits of the cloud (data available across all of your devices) and would grant developers more freedoms to create compelling experiences.
The future, I want is that some high schooler could create the next Google Docs without having to compete with Google on large scale data infrastructure and security but instead on user experience.
I think we're on the same page.
The only difference is that I think that the OS/Server/Filesystem is a big hinderance for many applications. I just want an environment where I can to execute arbitrary code.
My version would be
*> Every user has their own remote code execution environment.
One good candidate for the near future would be serverless WASM runtimes backed by serverless databases. (But you'll still have to store your codebase in a file system.)
Ultimately I’ve accepted that if the People aren’t willing to fight for these things, they don’t deserve them.
Same with general purpose computing: it's more accessible than at any time in history. Most people who use only a computing-based appliance like a smartphone today, simply would not have had a computer twenty years ago. Meanwhile I can buy a new Raspberry Pi 4 (definitely a general purpose computer) for less than 25 hours' minimum wage -- try doing that in 2002. The problem is not availability, or that someone is trying to quash it. The problem is that most people just are not interested. Those who are interested have at least as much access as they ever have.
Lorie Smith's case[1] seems to argue otherwise. If the law can be used to compel speech, then the slippery slope to tryanny is well-greased.
[1] https://restorationnewsmedia.com/articles/local-news/both-si...
What percentage of HN parents have tracking on their kids phone?
All of them.
All phones have "tracking" in that they're on a cellular network, so they can be tracked by a cell phone company. My son's phone was stolen at his school recently, but we had no way to recover it. What tracking software do people use on their kids phone? Perhaps I can use it to recover the phone if the next one gets stolen. Apparently since I'm the only parent here who doesn't have tracking for his kids, I want to make your claim true.