9 ms·
This is a FUD take. Are you griping about TPMs? I run Linux on every one of my personal machines and I run the software I want and I use my TPMs for useful thin
by jdoss 4y ago
This is a FUD take. Are you griping about TPMs? I run Linux on every one of my personal machines and I run the software I want and I use my TPMs for useful things. I keep hearing this cry about hardware manufactures are coming for our hardware freedoms and I have seen one instance this year where Lenovo did some stupid stuff[1] on a specific piece of hardware.
Now that I know that, I am not going to buy that specific hardware for my needs. If they follow onto their other models, I will find a hardware vendor that doesn't do stupid stuff. The market will adjust and you will have options like the Framework laptop to give you the freedom you want with your hardware.
Also, even with the above stupid stuff, you can disable secure boot for now and move on with your life.
1: https://mjg59.dreamwidth.org/59931.html https://mjg59.dreamwidth.org/59931.html
- josephcsible 4y ago> Are you griping about TPMs? I run Linux on every one of my personal machines and I run the software I want and I use my TPMs for useful things. There's no inherent problem with TPMs existing, since they do have some legitimate use cases. The problem with them is that they don't support owner override. Fixing that would make them useless for tyranny without impacting any legitimate use cases.
- worthless-trash 4y ago> don't support owner override Asus talks about how to disable it: https://www.asus.com/support/FAQ/1047459/ https://www.asus.com/support/FAQ/1047459/ As do many other manufacturers, its a thing.
- josephcsible 4y agoYou misunderstand what owner override is. It's not the ability to disable the TPM from functioning. It's having a way to tell the TPM to attest "yes, this system is totally running Microsoft/Hollywood-approved software" when it really isn't, if that's what the owner wants it to do.
- worthless-trash 4y agoI must misunderstand what override. Wouldn't the "override" term in this case be better served as being called "customised validated attestation state" ? Its doesn't roll of the tongue but correct terms matter.
- jdoss 4y agoThen don't run that software or don't buy that hardware in the first place? There are plenty of options here. A TPMs main role in our current hardware ecosystem is to provide device identity and attestation. This has been driven by businesses that want an easier time to bootstrap hardware for their needs. Which means controlling what software is run on company owned hardware. All of the FUD about lost of hardware freedom comes some from the fact that IT teams were tired of having to keep inventory and they needed a solution to enable the on boarding and off boarding of hardware. Look at what Apple is doing with their hardware and OS right now. It's not to take away more individual freedoms of their users. It is to help businesses and edu manage their Apple stuff stuff. The other vendors are trying to fix those pain points too. Managed device attestation is the SBOM new new hotness of 2023 and you don't need to be a big business to take advantage of it. Go look up what kind of cool things you can do with a TPM. For example https://systemd.io/CREDENTIALS/ https://systemd.io/CREDENTIALS/ is pretty cool. So is using it to make your life easier with LUKS encrypted volumes. https://gist.github.com/jdoss/777e8b52c8d88eb87467935769c98a95 https://gist.github.com/jdoss/777e8b52c8d88eb87467935769c98a...
- selfhoster11 4y agoThe “vote with your feet” argument has always been BS. The trend is overwhelmingly towards the introduction of DRM. It may be that there are options now, but soon there won’t be any.
- matheusmoreira 4y ago> Then don't run that software or don't buy that hardware in the first place? There are plenty of options here. Yeah, right. Just don't use any proprietary software. Just don't use any mobile app. Just don't buy any mainstream hardware and products. Enjoy all those ridiculously old FSF RYF certified laptops that won't run anything requiring the latest cryptographic user control features anyway. How in the world is this a solution? These corporations should be forced by law not to do this stuff. The hardware and software should be open and free and they should have no choice but to run on it on our terms if they want to reach customers at all. > Look at what Apple is doing with their hardware and OS right now. It's not to take away more individual freedoms of their users. You gotta be kidding me. It is literally impossible for a user to run software on an iOS device without Apple digitally signing it. "Manage their Apple stuff"? What a bunch of BS. More like create their own digital fiefdom where they own users, determine what they can and can't do and sell access to them to third party developers like they were cattle. You said it yourself, it's about "controlling what software is run on company owned hardware". We don't own these devices, the companies do. There is no freedom to be had here, we're all playing on their playgrounds.
- honkthegoose 4y agoNow try running your own build of Linux on a phone, or similar devices. It most probably won't work, because the likes of Qualcomm, Mediatek, Samsung, Huawei, Apple have locked down the hardware so you can only boot digitally signed firmware that matches public keys fused into the device. And that firmware does the same when loading the rest of the OS.
- selfhoster11 4y ago> Also, even with the above stupid stuff, you can disable secure boot for now and move on with your life. Except for Android phones (nominally, an open source OS), disabling the cryptographic protections results in the loss of your Safety Net status, and from now on a whole host of applications will refuse to work at all, or have reduced functionality. Make no mistake, I think this is the future of the PC.
- pooper 4y ago> from now on a whole host of applications will refuse to work at all This is pretty scary. I know I close the tab and move on when I see a notice on Firefox that says something to the effect of I must enable DRM to play media on this website (paraphrasing) but what if a bank or the government says the same? I think the answer goes back to we can't solve societal problems through technological means. We have to get involved in politics. If anything is a legal monopoly (such as taxes), it should use open protocols and be accessible through free software.
- matheusmoreira 4y ago> We have to get involved in politics. Yeah but how can we even win in such a space? These monopolistic corporations are already involved, they spend loads of money on lobbyists in order to legitimize their abuse. How can we possibly beat that?
- matheusmoreira 4y agoFUD? Normal desktop processors already come with features designed to protect memory and code from the prying eyes of users. Not to mention all the ring -5 code that is really in control of the computer. Smartphones now have attestation. They have hardware designed to cryptographically prove to its real owners that those pesky users haven't tampered with their phones. Software will refuse to run if this fails and it's not really something you can override by hacking on the OS. Face it, hardware today comes pwned from the factory. Hardware doesn't belong to us anymore, they belong to the "stakeholders" and they're only generously allowing us to use it so long we don't run any software they don't like.
- parker_mountain 4y ago> This is a FUD take We already live in this future. Apple has 25% of the phone market worldwide.