I am sure many people here have seen this, looks to me this is the direction society is slowly heading towards:
www.gnu.org/philosophy/right-to-read.en.html
I am sure many people here have seen this, looks to me this is the direction society is slowly heading towards:
www.gnu.org/philosophy/right-to-read.en.html
It's called Pluton, and (scarily) there is not much public technical information about it.
I think that ended up as some sort of trusted computing project; we were worried back then that linux was gonna be impossible to run in our PCs... well then PCs turned into smart-phones and even though they run linux (or iOS), we ain't choosing what they run
the name was something with a P? like palladium or something that has no P but sounds somewhat like that?... I'm saying I don't remember.
There's a nice quotation from the end of the How-To Geek article:
> As long as these measures don’t prevent us from running software we actually want to use, Pluton is a welcome development.
Indeed, Pluton could be beneficial, assuming you are on the side of fully trusting the Microsoft ecosystem front-to-back. Or scary if you don't trust the old 'Softy.
That being said, Apple's M1 architecture has a similar security chip installed as well. Some people legitimately want these walled gardens. We here at HN are probably more on the fringe side than the majority.
I think the rebels have to do better, to wit, they (we?) have to work smarter to make software that's just as functional but with far less code, so that it can be audited by an actual human being. Software engineers take a blase attitude about dependency bloat, but that must change. We also need to be ready to run on open hardware when it is released. Last but not least, we need to invent a way for the best hackers and geeks to sift through the software we run, people we trust to find flaws and exploits and not use them. I, for one, would gladly pay for this service, and I think thousands of others would, too.
What little there is, and even articles that are occasionally posted here about the dystopia it'll bring, seem to have vanished and/or be taken over by corporate mouthpieces spreading FUD in the comments. I can only see that as being the industry trying very, very hard to stop any dissent.
It's not, notice how easily it was circumvented in the story. In reality, it would not be possible to lend Lissa the computer with books, because there would be continuous FaceID checking who is the real person staring at the screen.
Also, in the story, "ten percent of those fees went to the researchers who wrote the papers", that would be a great upgrade for the current world.
In my experience the general public's notion of "general purpose computing" is "Well, my phone can do everything I need, isn't that general purpose computing?"
Is something that's being said only in advertisements, or by people conditioned by modern mass market tech to feel helpless, and define their needs as subset of what they know how to do on their device. In my meatspace circles, the people who say "oh my phone does everything that I need" tend to regularly ask me to help them with stuff they need, but their phone (or their knowledge of it) is, in fact, insufficient for.
The war is there, but it seems not all is lost just yet.
There are defensible arguments for secure boot, but they all thoroughly miss the larger picture in my opinion.
That said, I do believe that Windows will loose some endusers finally. Not the masses perhaps, but as long as there is an alternative, I am happy. If some apps forces me to use a specific machine or OS, I will not use it.
The components you are referring to confer a clear and important benefit to devices – a secure boot chain. This is the most foolproof way we know to prevent tampering or hacking a device.
The problem is that some of these secure boot chains don’t allow being overridden by users. Many do – the Pixel series of phones, the M-series of Apple laptops, and Windows S devices all allow “turning off” or “hijacking” their secure boot chains. The further problem if you can turn off secure boot is that these pieces of hardware often can’t then be turned back on with a different secure boot chain – say, one based on open source software. Debian and NixOS and other OSes already have zero-trust ways of verifying the integrity of their software using reproducible builds, but they can’t go the step further and have the hardware it is installed on do the same verification with some sort of signature.
GrapheneOS has figured out how to do this, and it leverages the secure boot chain of the Pixel device. It is very cool and I think a nice symbiosis between the hardware and open source software: https://grapheneos.org/build#generating-release-signing-keys
The next and more problematic part of what these technologies provide is integrity, which is the guarantee that on top of the boot being secure, the software being run is from the manufacturer and it behaves as the manufacturer intends. A lot of functionality currently relies on this guarantee of integrity: anti-cheat software, DRM software (Widevine, HDCP), transit cards, credit cards, driver’s licenses, etc. The technology manufacturers aren’t building this software because they want to, but because they have to. The Original Sin for the iPhone was carriers: at the time in 2008 they were really worried about unlocking and tethering, and the prank of the day was to put a flashlight app into the App Store that allowed tethering via a proxy. Rights holders, carriers, game manufacturers, etc all pressure tech companies to use integrity to solve their problems.
Many of these solutions have alternatives that don’t require OS integrity: if the government issues signed digital IDs, for example, then it wouldn’t matter what software is running on the phone. Some are tough and don’t have alternatives, like anti-cheat and DRM. DRM in particular is a complex US legal issue: anti-circumvention is straight up breaking the law. No solution would be comprehensive without changing the law.
Progress has been made, though! The fact that we have figured out ways of unlocking boot chains in a way that is acceptable to all of the large companies is awesome. Apple does it by being able to guarantee other secure boot chains on the device remain intact, and Google does it by ensuring the device is wiped. This took real engineering effort to do.
It’s important to push these companies to go further. An M1 iPad is almost identical to an M1 MacBook in hardware, and yet Apple only allows the latter to run Linux.
The comment is already a blog post, but another big problem is that these tools are great for anti-competitive purposes… which the government is increasingly taking a look at.
Why? Because we let it happen. We keep buying these things that have this function as a feature. The answer is simple but it demands dedication and resilience.
Simply stop buying them and using them. Yes, a boycott. There is no other answer because they are making ton of money doing things this way and the one;y way they will stop is if we stop making it profitable for them.
At some point, it's like telling people who don't want to drink dirty water that they should boycott their one and only water provider.
Maybe there would've been a chance if it was easy to prove that for every TPM chip they have to manufacture, they need to kill a small kitten. Or, if computing hardware was a commodity like a laundry detergent, so you could just choose an alternative that has near-identical specs, near-identical design and near-identical price, but comes without that one feature you don't want.
The companies don't care what you think, because this is a supplier-driven market. As a consumer, you can only choose out of what's available on the market. There's only so many players; barriers to entry are high, and they corrupt those who scale them[0]. They're going to keep making money and keep telling you what to buy, because they know you have no other choice.
----
[0] - You need a lot of up-front capital to start a hardware or software business. You're not going to pay for it out of your own pocket. The kind of people that will happily lend you money? They're the ones that will make sure your product fucks end-users over in every way possible, because they want to maximize returns on their investment. So even if you started wanting to do good, you're unlikely to be still doing it if you succeed.
It represents a black-and-white way of thinking about the problem when the entire point I am trying to make is that everything is gray and if you work in technology you need to understand the different shades of gray better.
Is your statement meant to be inclusive of, say, all laptops? I was under the impression that one can setup a machine to boot using personal keys rather than Microsoft keys: https://www.dannyvanheumen.nl/post/secure-boot-in-fedora/
The process of being able to use your own keys is certainly cool, but it is less impressive if anyone with physical access to the machine can also do that
Smartphone OSes have propogated their own curated walled-garden app stores, and then the desktop OS vendors follow suit. Soon it will simply not be possible to install unsigned, uncertified software on your computer, and that will be the end of GPC.
Microsoft Windows has had that for a while. It's called "Windows S".[1] Only software from the Microsoft store can be installed.
The lowest price laptops from Walmart run Windows S.
[1] https://support.microsoft.com/en-us/windows/windows-10-and-w...
https://support.microsoft.com/en-us/windows/switching-out-of...
Sometimes. For now. Machines in enterprise and school environments often have that option locked out.
I cannot fathom how Americans can point at the EU successfully forcing phone manufacturers to switch from 40 different types of proprietary chargers (we used to have different chargers for different models within a phone series ffs) to 1 and say “wow fuck the EU for taking away the freedom that obligated me to have a dedicated charging drawer”. That is the true mental gymnastics.
Same with privacy. What sane human thinks “yes please, farm, process and store into perpetuity all the intimate data points of my life”..
I'm mostly concerned about it locking out the development of new standards that aren't USB, even if that was an unlikely development anyway.
That's because, not in spite of the measures taken by the EU, which happened quite a long time ago.
We're talking about things like banking. Yes, some of this already affects services that are needed in practical sense to function in modern society, and it'll affect more of them over time.
> or create them [services that respect freedom]
Impossible, because the market is highly competitive, so services respecting freedom have no chance to survive for long, which also means almost no one is willing to try making them - and more importantly - funding them.
> or find alternative ways to meet the same need.
Increasingly close to impossible in a practical sense. Observe how many things are increasingly becoming mobile-first or mobile-only.
Banks, again, are a litmus test: there are plenty of new ones that don't have a web interface or physical presence, and the more traditional ones all strongly push users towards being dependent on the phone app (even if used only as an auth tool, it's still a hard dependency), which of course will happily use hardware and remote attestation to ensure you're not using a device that isn't a pristine, unmodded version of what the corporate world wants you to use.