6 ms·
Attestation of any type: A double edged sword, where you are guaranteed to lose freedom. Attestation entrenches, empowers, and enriches other entities that aren
by davidfiala 2mo ago
Attestation of any type: A double edged sword, where you are guaranteed to lose freedom. Attestation entrenches, empowers, and enriches other entities that aren't you.
Ironic how this post got upvoted in parallel to polar opposite in the #1 slot: "John Deere owners will get the right to repair equipment under FTC settlement" https://news.ycombinator.com/item?id=48838876 https://news.ycombinator.com/item?id=48838876
Engineers may debate about what-about-isms of vulnerabilities and counterexamples of TPM failures, but that misses the point: We should be debating about where society will be when devices you paid for serve other masters.
Probably we should just write/vibe/demand better software. Otherwise we're going to end up with a law demanding TPMs that watch more than just your firmware...
- solenoid0937 2mo agoYou don't understand the use case or audience of this article: > If your infra consistently enforces mTLS This is for mutual authentication in corporate infrastructure. Attestation is a critical security property for these environments.
- sfdlkj3jk342a 2mo ago> Attestation is a critical security property for these environments. No it's not. Every corporate network to which I've connected worked just fine without it.
- solenoid0937 2mo ago[flagged]
- sfdlkj3jk342a 2mo ago> Do you debate vaccines with your doctors too? If by "debate", you mean I take their advice into consideration and then make my own decision without blindly trusting them, then yes I do.
- solenoid0937 2mo agoI hope you put a lot more research into those debates than you did with this topic! I just don't understand why you'd have this overconfident hot take about a topic you clearly aren't familiar with. Like, try to understand the article subject and audience first?
- sfdlkj3jk342a 2mo agoI didn't claim to be an expert in this particular area of security, but I have enough common sense to know that remote attestation is not "critical" for a corporate network. Perhaps it has valuable use cases for very large companies that want complete control over their employee devices, but your claim is far too broad to hold.
- solenoid0937 2mo agoIt is not just about control, it is also about being able to trust the nodes in your network. It is not just about employee devices, but about literally every workload or host running in your corporate infrastructure.
- whiatp 2mo agoThis article is about using TPMs on servers, not employee devices.
- psd1 2mo agoI have enough common sense to know that the earth is flat and the sun revolves around it. That's why the sun comes up and why we don't fall off. I don't claim to be an expert, i just know that the experts are wrong.
- gspr 2mo ago> (Make claim that something is "critical".) > (Get challenged on that.) > omg you don't know anything, being without the thing is primitive and everyone sophisticated uses it. You can see how you can be accused of not actually presenting any arguments here, right? If you're gonna appeal to authority, at least back that appeal up with something.
- solenoid0937 2mo agoMy comment is fine. Appeals to authority are not inherently bad when the person doesn't know what they're talking about. Again, your doctor is more of an authority than you on medicine. It'd be hubris to think you'd understand the field better, no matter how smart you are. It's not my job to write an essay in the comments about why mutual authn with RA is desirable in corporate networks, and why the complaints about "freedom" are totally and utterly nonsensical in this context. This is something he can look up very quickly.
- gspr 2mo ago> Again, your doctor is more of an authority than you on medicine. It'd be hubris to think you'd understand the field better, no matter how smart you are. You are talking to strangers on the internet. When I go see my doctor, I initiate a conversation with a certified professional subjected to serious state scrutiny. I'd indeed do well to take their medical advice to heart. Nothing similar applies to reading your comments. Moreover, part of the reason that I do trust the doctor is that I know that their claims can be challenged and that the claims will withstand that challenge (this is in part ensured by certification and regulatory bodies, and in part by the medical community). You seem not to want to respond to such a challenge. Here's another doctor-based analogy: Suppose my doctor suggests I suffer from a specific medical condition. Even though I know that they are the professional, it wouldn't be insane for me to voice a concern I have that the condition does not seem to fit what I'm experiencing. That's not even really a challenge to their authority – it might just be a way for me to try to understand. Now, if the doctor responds to that concern by angrily tapping his diploma saying "you know nothing, I'm the professional, bow before me you moron!", I think I'd be wise to change doctors.
- fleventynine 2mo ago> Every corporate network to which I've connected worked just fine without it. Just because it appears to be working fine doesn't mean you are in control of it. Without hardware attestation, how do you know the machines are running the software you think they are?
- darkwater 2mo agoMy spouse's local Linux account on my laptop works fine with their password set as their username as well. Is it technically secure, though?
- deleted 2mo ago[deleted]