4 ms·
Remote attestation or not, "Software freedom" fighters should understand that things happen based on some user base need. Somebody needed this and they added it
by robot 4y ago
Remote attestation or not, "Software freedom" fighters should understand that things happen based on some user base need. Somebody needed this and they added it, whoever needs it doesn't care if they can't run linux on it. If the user cares about running anything else on the hardware, they will add a way to disable the feature. it is all about the user need.
if you are a secondary priority user on some hardware, the way to fix it is to focus on becoming important enough to be prioritized instead of fearing some technology will limit things.
- grishka 4y ago> things happen based on some user base need Of course not. Things happen based on what investors and developers want. Users are very much secondary. They're a nuisance. If things did really happen based on some user-base need, would we have had Instagram or Facebook in their current form?
- robot 4y agoThere is some kind of balance since both of those are free. I'm sure they prioritize user engagement and any loss of users is inadvertent.
- Rebelgecko 4y agoI think so? FB exists in its current form because they're worried about users preferring TikTok
- grishka 4y agoSee, it's them being worried about it. Users are totally fine with there being different forms of social media. That is what users want. No one ever asked other social media companies to add TikTok-like functionality — they already have actual TikTok for that.
- deleted 4y ago[deleted]
- MereInterest 4y agoSomebody wanted this, but it might not be a user, and it might not fill any user need whatsoever. If I am the primary user of the hardware, my wants take precedence over anyone else, including the manufacturer and the software vendors.
- robot 4y agoagreed, your wants take precedence. If there are enough buyers like you who care about hardware freedom they'll drop this feature.
- MereInterest 4y agoI was not making a market-based argument, as the preferences of other buyers is irrelevant. That Having purchased the hardware, that I wish to run software is the only justification required. This is not something that is amenable to market-based solutions, as the market contains bad actors pushing for infringement of my ability to run software.
- blendergeek 4y ago> "Software freedom" fighters should understand that things happen based on some user base need. I wish that were true. However, I think the movie Tron (1982) sums this up very nicely. From the movie Tron: > Dr. Walter Gibbs: That MCP, that's half our problem right there. > Ed Dillinger: The MCP is the most efficient way of handling what we do! I can't sit here and worry about every little user request that comes in! > Dr. Walter Gibbs: User requests are what computers are for! > Ed Dillinger: Doing our business is what computers are for. We are now moving toward a world where all computers have a "MCP". No, it is not to solve user problems, it is to do the business of the corporations that designed it.
- jauer 4y agoThis. All these comments (and this article) worried that this is MS coming to take their Linux or whatever are missing that this is something their biggest customers want. We need this in our corporate client device fleet to counter specific threats. We need this in our servers for the same reason — we do remote attestation today for Linux servers in semi-trusted locations. We’ve conveyed to our vendors that this is a desired capability in next-gen network equipment. We’re not doing this to control data once it’s on an end-user’s computer. We’re doing it because we have a regulatory (and moral) obligation to protect the data that is entrusted to us. We’re not Intel/AMD/NVIDIA/etc’s largest customer, but when we defer orders or shift vendor allocation it gets mentioned in their quarterly earnings reports. They tend to listen when we ask for features, and when our peer companies (not to mention governments) ask for the same thing because we have similar data security requirements? Cloud and Business products is what, ~2/3rds of Microsoft’s revenue at this point? This isn’t being driven by the MPAA or whoever looking for better ways to screw over consumers.
- userbinator 4y agoWe’re doing it because we have a regulatory (and moral) obligation to protect the data that is entrusted to us. The same insane regulations that were probably the result of corporate lobbying are now the excuse for these hostile features? WTF?
- jauer 4y agoThe regulations that were the result of lobbying by privacy and digital sovereignty advocates, contrary to the lobbying interests of Big Tech(tm)? > are now the excuse for these hostile features These features may be hostile if you don't control your own root of trust or if your vendor burns fuses prior to selling a device to you. If you were expecting otherwise, in that context they sold you a defective product. Those same features are beneficial if you run your own root of trust. They help maintain control over your devices and increase confidence that they have not been coopted by your adversaries.
- salawat 4y ago
- matheusmoreira 4y ago"Somebody" means billion dollar corporations that already have way too much power over people. Their ability to want and actually realize this bleak attestation future needs to be regulated out of existence.
- cesarb 4y ago> Somebody needed this and they added it, whoever needs it doesn't care if they can't run linux on it. Originally, the ones who "needed" features like this this are the big content distributors. Without these features, it's too easy for normal people to extract content and give copies of it to their friends and family. As a parallel development, another one who "needed" features like this is Microsoft, for a different reason. They were taking reputational damage from malware, and needed a way to prevent malware from running before their operating system kernel (malware loading after the operating system kernel could be contained by the normal security mechanisms like ACLs). These two development threads had enough in common that they ended up merging together, and those who want to prevent copying content can now point to security as an excuse. And yes, neither of these two groups care if you can't run Linux on your own devices. > if you are a secondary priority user on some hardware, the way to fix it is to focus on becoming important enough to be prioritized instead of fearing some technology will limit things. I fully agree that this is our best defense. In fact, the only reason we can still run Linux on our desktops and notebooks is that, when SecureBoot was developed, Linux was already important enough. However, this could only happen because Linux had time to grow and become important enough (while being a "secondary priority user" of the hardware) before things started to become limited. Had SecureBoot come before Linux became important enough, running third party operating systems would not have been allowed, and Linux would not have had a chance to grow and gain importance.
- jstanley 4y ago> malware loading after the operating system kernel could be contained by the normal security mechanisms like ACLs If this were true, how would the malware ever get itself to the point where it is loaded before the kernel is?