That is, bootloader locking and remote attestation should be forbidden by law.
666 karma · joined April 30, 2022
That is, bootloader locking and remote attestation should be forbidden by law.
It's not a large amount of money for the US but it's 3 billion dollars...
About that, I imagine the millisecond that you can validate using remote attestation that a client has no adblockers, Cloudflare will add a remote attestation "gateway" (like the one they have now with the captcha) that will, overnight, give every Cloudflare customer (so half of the internet) the ability to block users that may have adblockers.
It's simply too juicy of a service for these people.
Remote Attestation establishes a root of trust that can be used to verify that all of the software down the line is "approved":
- You won't be able to browse sites or use apps with ads unless you run a 'trusted' device, OS and browser that does not block ads.
- You won't be able to browse sites with captchas unless you run a 'trusted' device, OS and browser that does not allow bots to interact with the browser.
- You won't be able to run Netflix unless you run a 'trusted' device, OS and browser so that you can't record the content.
- You won't be able to play online games unless, again, you run a 'trusted' device and OS so that you cannot cheat, or more importantly modify it in any way (why would you purchase skins if you can mod them in?).
- You won't be able to use online banking unless you use a trusted OS because banks.
Remote Attestation is pretty terrifying and it will be here soon unless it is regulated out of existence, which is unlikely.
In fact that is how most phones (that still have an unlockable bootloader) do it, the button is in the developer options which if you reset the phone you cannot get to without having access to the linked Google account.
Now, can we get rid of hardware remote attestation and impossible-to-unlock bootloaders please?