Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is a FUD take. Are you griping about TPMs? I run Linux on every one of my personal machines and I run the software I want and I use my TPMs for useful things. I keep hearing this cry about hardware manufactures are coming for our hardware freedoms and I have seen one instance this year where Lenovo did some stupid stuff[1] on a specific piece of hardware.

Now that I know that, I am not going to buy that specific hardware for my needs. If they follow onto their other models, I will find a hardware vendor that doesn't do stupid stuff. The market will adjust and you will have options like the Framework laptop to give you the freedom you want with your hardware.

Also, even with the above stupid stuff, you can disable secure boot for now and move on with your life.

1: https://mjg59.dreamwidth.org/59931.html



FUD?

Normal desktop processors already come with features designed to protect memory and code from the prying eyes of users. Not to mention all the ring -5 code that is really in control of the computer.

Smartphones now have attestation. They have hardware designed to cryptographically prove to its real owners that those pesky users haven't tampered with their phones. Software will refuse to run if this fails and it's not really something you can override by hacking on the OS.

Face it, hardware today comes pwned from the factory. Hardware doesn't belong to us anymore, they belong to the "stakeholders" and they're only generously allowing us to use it so long we don't run any software they don't like.


Now try running your own build of Linux on a phone, or similar devices. It most probably won't work, because the likes of Qualcomm, Mediatek, Samsung, Huawei, Apple have locked down the hardware so you can only boot digitally signed firmware that matches public keys fused into the device. And that firmware does the same when loading the rest of the OS.


> Also, even with the above stupid stuff, you can disable secure boot for now and move on with your life.

Except for Android phones (nominally, an open source OS), disabling the cryptographic protections results in the loss of your Safety Net status, and from now on a whole host of applications will refuse to work at all, or have reduced functionality. Make no mistake, I think this is the future of the PC.


> from now on a whole host of applications will refuse to work at all

This is pretty scary. I know I close the tab and move on when I see a notice on Firefox that says something to the effect of I must enable DRM to play media on this website (paraphrasing) but what if a bank or the government says the same?

I think the answer goes back to we can't solve societal problems through technological means. We have to get involved in politics. If anything is a legal monopoly (such as taxes), it should use open protocols and be accessible through free software.


> We have to get involved in politics.

Yeah but how can we even win in such a space? These monopolistic corporations are already involved, they spend loads of money on lobbyists in order to legitimize their abuse. How can we possibly beat that?


> Are you griping about TPMs? I run Linux on every one of my personal machines and I run the software I want and I use my TPMs for useful things.

There's no inherent problem with TPMs existing, since they do have some legitimate use cases. The problem with them is that they don't support owner override. Fixing that would make them useless for tyranny without impacting any legitimate use cases.


> don't support owner override

Asus talks about how to disable it:

https://www.asus.com/support/FAQ/1047459/

As do many other manufacturers, its a thing.


You misunderstand what owner override is. It's not the ability to disable the TPM from functioning. It's having a way to tell the TPM to attest "yes, this system is totally running Microsoft/Hollywood-approved software" when it really isn't, if that's what the owner wants it to do.


Yeah. There's little point in overriding anything since these days everything requires remote attestation that software hasn't been "tampered with". What good is installing custom software if the applications we need refuse to run because we "tampered" with stuff?


I must misunderstand what override. Wouldn't the "override" term in this case be better served as being called "customised validated attestation state" ? Its doesn't roll of the tongue but correct terms matter.


Then don't run that software or don't buy that hardware in the first place? There are plenty of options here.

A TPMs main role in our current hardware ecosystem is to provide device identity and attestation. This has been driven by businesses that want an easier time to bootstrap hardware for their needs. Which means controlling what software is run on company owned hardware.

All of the FUD about lost of hardware freedom comes some from the fact that IT teams were tired of having to keep inventory and they needed a solution to enable the on boarding and off boarding of hardware. Look at what Apple is doing with their hardware and OS right now. It's not to take away more individual freedoms of their users. It is to help businesses and edu manage their Apple stuff stuff. The other vendors are trying to fix those pain points too.

Managed device attestation is the SBOM new new hotness of 2023 and you don't need to be a big business to take advantage of it.

Go look up what kind of cool things you can do with a TPM. For example https://systemd.io/CREDENTIALS/ is pretty cool. So is using it to make your life easier with LUKS encrypted volumes. https://gist.github.com/jdoss/777e8b52c8d88eb87467935769c98a...


> Then don't run that software or don't buy that hardware in the first place? There are plenty of options here.

Yeah, right. Just don't use any proprietary software. Just don't use any mobile app. Just don't buy any mainstream hardware and products. Enjoy all those ridiculously old FSF RYF certified laptops that won't run anything requiring the latest cryptographic user control features anyway.

How in the world is this a solution? These corporations should be forced by law not to do this stuff. The hardware and software should be open and free and they should have no choice but to run on it on our terms if they want to reach customers at all.

> Look at what Apple is doing with their hardware and OS right now. It's not to take away more individual freedoms of their users.

You gotta be kidding me. It is literally impossible for a user to run software on an iOS device without Apple digitally signing it. "Manage their Apple stuff"? What a bunch of BS. More like create their own digital fiefdom where they own users, determine what they can and can't do and sell access to them to third party developers like they were cattle.

You said it yourself, it's about "controlling what software is run on company owned hardware". We don't own these devices, the companies do. There is no freedom to be had here, we're all playing on their playgrounds.


Not all proprietary software currently insists that you get into a TPM-mediated Dom/sub relationship with its developers. Its currently possible, and might be ethically necessary, not to buy those ones, and instead to buy the other ones.

But it's also probably important to pursue a political avenue as well. The government should absolutely not be using this stuff, and shouldn't be advising citizens to do it to access government services. We could even pass a law requiring purchased hardware and software to meet a fiduciary standard towards its users.


> You gotta be kidding me. It is literally impossible for a user to run software on an iOS device without Apple digitally signing it. "Manage their Apple stuff"? What a bunch of BS. More like create their own digital fiefdom where they own users, determine what they can and can't do and sell access to them to third party developers like they were cattle.

Then don't buy Apple products? I totally agree with you in spirit in a lot of your points and I want more freedoms on my hardware. I just understand why we are in this situation as users. We don't have the market power like businesses do when it comes to hardware and most consumers don't care or don't understand their loss of freedoms.

> You said it yourself, it's about "controlling what software is run on company owned hardware". We don't own these devices, the companies do. There is no freedom to be had here, we're all playing on their playgrounds.

Yep, 100% agree here. There are zero freedoms when you are using company owned devices. They have every right to lock them down to the playground they desire for their users. The hardware market is building what their end users want. It just so happens their biggest paying end users are businesses.


That argument boils down to "if there's something you dislike about society, feel free to live a hermit life in the woods instead". That's not an argument, that's an ultimatum.

In order to receive my salary, pay taxes, fulfill children's schooling, and a myriad of other things there are plenty of proprietary software involved that requries a full hardware attestation to prove that the no part of the software stack is under user control.

It is completely unfounded to call this FUD. It is a fact of modern life. I do condone it because there are many obvious economic and political problems with it already, and could easily see how it could get much worse before it gets better. So far I have been able to isolate these "0wned" devices from the rest of my digital life, but that rest is getting increasinly marginalized.


The “vote with your feet” argument has always been BS. The trend is overwhelmingly towards the introduction of DRM. It may be that there are options now, but soon there won’t be any.


I can see why people would want that, but I can also see why people would want to have an additional certified copy of an important document, artwork, or piece of sports memorabilia, if that’s what the owner of that object wants.


> certified copy of an important document, artwork, or piece of sports memorabilia, if that’s what the owner of that object wants

I don't see how this is relevant. Real world objects can't be exactly duplicated, certificates of authenticity make sense in that context. Data is just bits, any copy will be exact reproductions. There is no need to certify that.


If you had an exact copy of the data/OS/config of the system in question, it would obviously validate (properly) as being unmodified.

What this thread is discussing is modified copies validating as unmodified copies.


Yes but I don't see how that's in any way comparable to wanting a certified collector's item.

Validating our software as unmodified is really just digital oppression. It's a violation of our dignity as users and human beings. We have all these corporations shipping literal data harvesting and advertisement displaying malware and there's not a thing we can do about it because they have usurped control of our computers.

Who does this "validation" serve? Not us. It serves the "stakeholders". It gives them confidence that we won't be running software that harms their interests.


> This is a FUD take

We already live in this future. Apple has 25% of the phone market worldwide.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: