3 ms·
not exactly modern, or dystopian - see also paper money, for instance, which may be owned by you, but is controlled by another entity and contains features maki
by grkvlt 5y ago
not exactly modern, or dystopian - see also paper money, for instance, which may be owned by you, but is controlled by another entity and contains features making it hard to modify or duplicate.
the analogy is flimsy, i suppose (paper thin, lol?) but the problem is that the user cannot be trusted to be non-malicious. however, with esim technology i had assumed the trust was assured using keys owned by the proivider, so i'm not sure whether there's something else going on here?
- grishka 5y agoMoney is only valuable because the society makes it so, and especially because governments only accept taxes in their own currency. But if you own a banknote, it's fully yours. You can spend it on anything — including something illegal like drugs. Or you can draw something on it thus invalidating its value. The government that issued it doesn't have a say in any of this. But with modern locked-down electronics, you could only do what the manufacturer intends, and nothing more. Continuing with monetary analogies, it's like a credit card that only works for things your bank considers "good" for you.
- lxgr 5y agoSandboxed trusted computing actually offers a way out of this dilemma: Rather than having an entire phone/computer etc. locked down (so that some third party can trust it), there is only a trusted subsystem that can interact with the larger system only in limited and well-defined ways. Microsoft's plans for the TPM back in the early 2000s have given the entire concept of trusted computing a bad reputation, but besides DRM, there are many legitimate use cases for it that are not anti-consumer/anti-freedom.
- grishka 5y agoSure. Cloud servers are a good one. But I still see no benefit for the end user to lock down any consumer devices like that. It only benefits the device manufacturers themselves. Like, you know, Apple forcing its online services onto people literally by burning stuff into silicon. I don't have a problem when hardware and software are tightly integrated. I do have a problem when said software isn't modifiable and has a hard dependency on servers you can't control and can't self-host. Let people modify their modem firmware, just make sure they understand what they're doing. But they might interfere with other people's service, you say? They could as well do that with a $300 SDR, or they could buy a purpose-built cellular jammer. Let governments enforce their laws, don't make something technically impossible because making it possible might enable someone to break a law.
- lxgr 5y ago> with esim technology i had assumed the trust was assured using keys owned by the proivider, so i'm not sure whether there's something else going on here? There is trust both ways: - You trust the provider's keys so that nobody can later intercept your traffic, as the keys encrypted under it will later be used to encrypt and authenticate that traffic. (Of course the networks themselves have ample security holes and allow for lawful interception, but that's another topic.) - The provider trusts your eSIM to not expose your keys to the baseband or application processor ever. If it wasn't for that, the provider's invoices might not be defensible in court in case of a billing dispute: You could easily claim that you've been subject to malware that stole your authentication keys and then went on to call toll numbers for hours. Theoretically, the first point is only addressing your own risk, but it seems like the eSIM designers seem to have taken the position they did (mandatory GSMA PKI signatures). Unfortunately, this also means that "homebrew eSIMs" are out of reach for now. The latter is very similar to the idea of chip credit and debit cards: The issuer relies in both users and fraudsters not being able to extract and duplicate a card's keys, so that use of these keys can be seen as proof of the authentic card being involved.