Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Magnusmaster
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
Magnusmaster
1mo ago
Locked down devices will never preserve privacy since the government can just mandate spyware that you won't be able to remove. There is no form of digital ID that isn't evil, but anything requiring attestation is super evil.
2.
▲
by
Magnusmaster
3mo ago
Just say that the government will control every single device that's controlled to the Internet and they can add government viruses that you can't remove and they can remotely control all of your devices and brick them if you try
3.
▲
by
Magnusmaster
3mo ago
Exactly. And the funny thing is that the EU Age Verification App seems to be vulnerable to relay attacks anyway.
4.
▲
by
Magnusmaster
3mo ago
I expect the government will require ISPs to only allow connection from approved operating systems that only allow installation of approved apps so we can't do this. Not in the short term, but eventually.
5.
▲
by
Magnusmaster
3mo ago
Probably by forcing VPNs to only allow approved operating systems to connect to the Internet via hardware attestation, then those operating systems will only allow users to install signed apps, and only government-approved VPNs will be allo
6.
▲
by
Magnusmaster
3mo ago
I'm not sure that is even possible with Secure Boot
7.
▲
by
Magnusmaster
3mo ago
Zero knowledge proofs exist in theory, but none of these age verification laws that are introduced use them, probably on purpose. I'm certain that every government will want to know what sites everyone visits.
8.
▲
by
Magnusmaster
4mo ago
The people pushing for age verification have already said that they want to know who's behind every account on every website on the entire Internet. They won't accept any open or privacy-preserving standard.
9.
▲
by
Magnusmaster
4mo ago
The third world is also pushing Digital ID. In fact they would love it even more than the first world as it would allow for even more totalitarianism.
10.
▲
by
Magnusmaster
4mo ago
And it was a huge mistake. The laws are the same for everyone. If Apple can do this then so can Google.
11.
▲
by
Magnusmaster
6mo ago
Problem is a lot of apps require a locked-down device. You can't use a phone that isn't locked down in most of the world. And it will spread to PCs eventually.
12.
▲
by
Magnusmaster
6mo ago
The EU Digital Wallet requires hardware attestation so only it only works on locked-down government-approved OSes. That opens the door for government control of all electronic devices.
13.
▲
by
Magnusmaster
6mo ago
Zero knowledge proofs stops corporations from tracking you, but they don't stop the government from tracking which websites you visit. They also require hardware attestation for them to work, which means you will be only allow to use a
14.
▲
What's the deal with "age verification" and computers?
(rudd-o.com)
10 points
by
Magnusmaster
6mo ago
|
0 comments
15.
▲
by
Magnusmaster
8mo ago
I doubt banks or the government would ever white list something like Lineage that's not made by some megacorporation. Also IIRC most phones don't allow you to relock the bootloader after flashing a custom ROM.
16.
▲
by
Magnusmaster
8mo ago
Most banks don't know hardware tokens are a thing. They want everyone to use their app.
17.
▲
by
Magnusmaster
8mo ago
To avoid confusion, the actual name is Trusted Platform Module.
18.
▲
by
Magnusmaster
8mo ago
They won't need to do that. Once Google Play Integrity starts using remotely provisioned keys in a few years it will be impossible to hide root without exploiting a hardware or firmware vulnerability.
19.
▲
by
Magnusmaster
8mo ago
You don't own your PC either. All modern PCs have a Trusted Platform Module that the authorities can and will use to lock down PCs eventually. Multiplayer games are already using hardware attestation on PC for anti-cheat.
20.
▲
The Vietnam government has banned rooted phones from using any banking app
(xdaforums.com)
547 points
by
Magnusmaster
8mo ago
|
620 comments
21.
▲
by
Magnusmaster
8mo ago
The Vietnamese government has mandated all banking apps to detect if either the phone has been rooted, the bootloader has been unlocked, or ADB is enabled and force quit if that's the case.
22.
▲
by
Magnusmaster
9mo ago
You already need to submit to iOS or stock Android for a myriad of banking or government apps that use remote attestation to verify that you are running "untampered" software. Remote attestation is evil.
23.
▲
by
Magnusmaster
1y ago
If you live in the EU please complain about Google's developer registration (and other anti-competitive stuff such as Google Play Integrity) here. The EU is asking for people's feedback regarding the Digital Fairness Act. https:&
24.
▲
by
Magnusmaster
1y ago
There is such a smartphone. But then you can't use your bank's app because it uses hardware attestation to ban alternative operating systems, and most banks require the app for 2FA or don't have a functional web portal at all
25.
▲
by
Magnusmaster
1y ago
There will never be a third large OS unless Google Play Integrity is legislated out of existence. And it looks like governments like Google Play Integrity so that won't happen
26.
▲
by
Magnusmaster
1y ago
The end point is going to be you will only be able to connect to the Internet with a device that passes hardware attestation so people won't be able to tinker
27.
▲
by
Magnusmaster
1y ago
No
28.
▲
by
Magnusmaster
1y ago
Unfortunately I don't think they will let you do that.
29.
▲
by
Magnusmaster
1y ago
It's already happening for several apps such as banking apps, payment apps, government ID apps, etc.
30.
▲
by
Magnusmaster
2y ago
Magisk only works because Google still supports devices that don't support hardware attestation. Very soon you won't be able to fool Play Integrity without hacking the TEE
More ›