4 ms·
BitLocker type solutions don't rely on remote attestation. RA has never really taken off in any context. Regardless, arguments against remote attestation are a
by native_samples 4y ago
BitLocker type solutions don't rely on remote attestation. RA has never really taken off in any context.
Regardless, arguments against remote attestation are always very tricky. You're acting like it's morally clear cut but it's not.
RA is designed to stop you lying about what you're running to other people. It doesn't stop you running things, but it may mean others choose not to trade or engage with you based on what you're doing with the computer. So this is a direct translation to standard libertarian philosophy. You can choose your own terms but you can't force your preferred terms on others - you have to negotiate a contract that's mutually acceptable and then that contract needs to be enforced. RA is a kind of technologically enforced contract, instead of relying exclusively on the legal system.
That's why arguments that RA is evil always skip a few steps. The argument goes:
- I want to run X (typically some Linux distro)
- Some service Y won't trade with me unless X will do Z (typically enforcing some sort of agreement e.g. anti-cheat or license).
- X chooses not to do Z but I want Y to service me anyway. So I want to lie to them and feel entitled to being able to do that without being caught. This is moral because Linux.
Often with a helping of "I'm afraid that actually service Y might be most services".
The concerns here are valid - it would suck to no longer be able to use Linux with various remote services - but if you look at how the TPM and related tech are designed there's no actual technical reason you couldn't make Linux satisfy remote attestations. It's simply that Linux users would usually refuse to do so on philosophical grounds. Well, that's fine, but from a political and philosophical perspective it's reasonable for your counterparty to want some assurance that you'll actually implement the agreement you're claiming you will.
- car_analogy 4y ago> So this is a direct translation to standard libertarian philosophy. You can choose your own terms but you can't force your preferred terms on others - you have to negotiate a contract that's mutually acceptable and then that contract needs to be enforced. RA is a kind of technologically enforced contract [..] Some service Y won't trade with me unless X will do Z (typically enforcing some sort of agreement e.g. anti-cheat or license). What can I say but thank you - you've distilled the problems with the TPM much better than I have. What you describe is exactly what I fear. Look at how these contracts are "negotiated" today - the consumer either accepts, or goes to live in the woods ("I'm afraid that actually service Y might be most services".) And the terms are one-sided at best, usually curtailing a bunch of important rights (mandatory arbitration, bans on publishing benchmarks, anti-reverse-engineering or indeed any kind of in-depth examination of functionality, such as when Facebook barred researches from gathering data from volunteers on what ads they were showing, bans on scraping publicly-accessible data - good luck comparing prices,.. you get the picture) So what kind of contracts do you think we'll negotiate, without even the thin pretense of a fair legal system protecting us, and when "our" machines enforce their unbreakable chains? If I'm being charitable, I'd put the odds that the overall effect of this expansion of contract law will be to our benefit as "slim".
- fuzzfactor 4y ago>when it comes to Pluton, or the AMD and Intel management engines, they're making sure you can't buy a product without them at any price. Not only that but under the guise of "recycling", many 18-wheelers of perfectly functional PCs are being destroyed rather than re-purposed and these are primarily the ones powerful enough to run the latest OS's. Anything decently powerful lacking the encumbrance of the hardware ME/TPM generation is the prime target of the agressive destructive effort.
- native_samples 4y agoYou picked a bunch of conditions you don't happen to like and then projected this onto the technology along with a giant helping of victimhood, but again, RA is morally neutral. It's like encryption, it can be used for things you may agree or disagree with but the tech is just a tool. In this case it's just a way to enforce agreements. So here are some agreements that maybe you'd actually like to enforce on other people, using the exact same technology. 1. Cloud privacy. RA and related tech let's you request a remote attestation from the cloud provider that proves your VM memory is encrypted such that the hardware provider can't read it. This means you can compute in the cloud and not be spied on, not even if the legal system in the remote jurisdiction suddenly demands it. You might think cloud providers would never offer this but you'd be dead wrong. Both Azure and GCP offer RA in which you are the one checking them and they offer it today. 2. Blocking spamming without needing captchas or modern JavaScript based equivalents. In turn that means you can now much more easily self host email and retain control and privacy currently sacrificed to big email providers. 3. Copyleft enforcement. Yes really. It'd require toolchain integration but it's possible. 4. Eliminating backdoors inserted by cloud CI systems. They prove what compilers they're using via RA. Etc. This is just a few examples. And that's why your argument is frankly morally flawed. Agreements and contracts are something everyone relies on whether they realize it or not. The fix for terms you don't like is not to demand leaky enforcement but, as always, market competition. If you hate Oracle's "no publishing of benchmarks" clauses - which are by the way unenforceable with RA anyway so that's a bad example to pick - then use postgresql instead. At any rate, it's all rather irrelevant. You have much more bargaining power than you think and that is in fact why RA has never taken off. Outside of very controlled environments like games consoles or cloud VMs it's considered too complicated and excludes too many users who don't have the right hardware etc. Consumers effectively "negotiate" by picking services compatible with what they've got.