4 ms·
From a technical perspective, of course it is possible to give users control of the trust on the devices they ostensibly own, rather than giant megacorps, and I
by error503 4y ago
From a technical perspective, of course it is possible to give users control of the trust on the devices they ostensibly own, rather than giant megacorps, and I remain extremely unconvinced that this leads to a meaningful loss of security or privacy for those users. From a socioeconomic perspective, it's a much bigger question; the allure for those megacorps is far too strong and the economics of the industry makes it hard for society to wrest power from them, and for some reason people seem mostly okay with this status quo.
It seems to me that it's inevitable that if we let these megacorps control our devices, they will use it against us in one way or another. The only way for us as users to actually have freedom, security, and privacy is if we can control what entities the device trusts ourselves. We must create choice where the corps would rather we have none.
I will also point out that I consider Apple's rent seeking and censorship, that is more or less literally impossible to avoid, to be unethical use of this power they wield over users, and a pretty clear and meaningful way that users are harmed by it. In very concrete ways it can be considered more harmful than malware. But few seem to care enough to ask for control of their devices back, and in many of these threads more seem willing to jump to the defence of these practices than see them as a problem.
- danaris 4y agoOh, this is certainly a question primarily about the social aspects and second-order effects. The technical perspective is much more solvable, though still not, I think, a solved problem. The problem with "I control my device" is, and always has been, twofold: First, that when some malware gets in, it looks like you. Second, that people who are not technically savvy will not be able to use that control to protect themselves, but will instead very often have it used against them. The former of these is, in fact, a technical problem; the latter is social, and much harder to control for.
- error503 4y ago> First, that when some malware gets in, it looks like you. I don't see what this has to do with trust. Whether or not there is a secure trust chain, malware can likely impersonate you. > Second, that people who are not technically savvy will not be able to use that control to protect themselves, but will instead very often have it used against them. If people are going to ignore the flashing red banners that pop up when they try to override the trust store that comes with their device, then that is a price we have to pay, IMO. We accept in the rest of our lives that some things are dangerous, and while we erect many barriers to make those things more difficult, we recognize that is the price of freedom. People will do them anyway, and some will be harmed. It doesn't have to be frictionless, it just has to be possible. Is there a spate of malware going around that involves users installing new keys in their UEFI secure boot trust store? I haven't really heard of this. I also haven't really heard of a spate of malware using Android's developer mode that is pretty easy to enable, if you know how. I think the risk involved in giving users ultimate control of the device's trust store is greatly overblown.