5 ms·
> Ultimately it's rooted in economics. People like free stuff, and the only way to give it to them is to monetize it indirectly via ads and surveillance. It's
by Bran_son 3y ago
> Ultimately it's rooted in economics. People like free stuff, and the only way to give it to them is to monetize it indirectly via ads and surveillance.
It's more than economics - they actively attack privacy and user control. E.g. DRM anti-circumvention laws, the impossibility of buying a CPU without Intel Management Engine (or AMD equivalent) unless you're a government agency [1], forcing the Trusted Platform Module on users, the gradual vanishing of rootable-phones and proliferation of apps that require a non-rooted phone, no more non-smart TVs, etc. Countless cases where there are no freedom-respecting options available for commoners at any price.
[1] https://en.wikipedia.org/wiki/Intel_Management_Engine#Commercial_ME_disablement https://en.wikipedia.org/wiki/Intel_Management_Engine#Commer...
- csdvrx 3y agoThere's a huge difference between TPM and IME: with TPM, you can put your own keys, and use the TPM to refuse payloads not signed with your keys (ex: a Windows install thumbdrive) With AMT/IME or BootGuard, you don't get that control: you can't replace the bootguard keys (as it's a way to kill the secondary market of CPUs being resold and used in a different motherboard) and with AMT you can't fully disable it unless you're a government agency as you said. The technology isn't bad, it's the actual implementation that's wrong by avoiding certain features which could give the user more freedom.
- wkat4242 3y agoYeah security is good but it needs to serve the user, meaning they must be able to have full control over it if they so desire. I also hate Apple's Mac and iOS closedness. Sure, on Mac you can disable SIP but you will disable its security completely, and you will also lose access to some of the OS features. There should be a way to sign your own code and simply allow that to be trusted with full protection, just like it is on generic intel systems with secure boot where you can easily add your own signing keys.
- bpye 3y ago> I also hate Apple's Mac and iOS closedness. Sure, on Mac you can disable SIP but you will disable its security completely, and you will also lose access to some of the OS features. On an Apple Silicon Mac you can have multiple operating systems installed, with different security configuration. It's totally possible to have both Asahi and macOS installed without disabling any security features in macOS.
- mjg59 3y ago> with TPM, you can put your own keys, and use the TPM to refuse payloads not signed with your keys (ex: a Windows install thumbdrive) No, that's UEFI Secure Boot, which doesn't use the TPM - it's entirely handled on-CPU. Most of the keys on a TPM are under user control (but aren't involved in the boot process) other than the EK, which is generated at manufacture time and will be consistent for the lifetime of the TPM.
- csdvrx 3y agoIndeed, it's s simplification. If you want to go down the TPM rabbit hole, read this interesting comment about IEEE 1667: https://github.com/MicrosoftDocs/windows-itpro-docs/issues/5429#issuecomment-554661734 https://github.com/MicrosoftDocs/windows-itpro-docs/issues/5...
- kube-system 3y agoAll of those issues have economic explanations. DRM exists to protect the revenue streams of content owners. IME exists because Intel’s big customers want it and the people who don’t want it don’t have enough money for a custom SKU. TPM exists just because it’s a good security feature that the industry has demanded. Mainstream phones run non-privileged because businesses and the general public do not need root, and those who do want those features are a niche market. TVs mostly have smart features because subsidized TV with more features sell better than more expensive TV with fewer features. Corporations optimize for money, they’re indifferent to privacy, they’ll sell whatever people are willing to buy that makes them the most money.
- Bran_son 3y ago> IME exists because Intel’s big customers want it and the people who don’t want it don’t have enough money for a custom SKU I addressed this - systems without IME exist, but are not available for purchase, for any price, except for governments. That's not economics. > TPM exists just because it’s a good security feature that the industry has demanded Industry demands it, and OS and CPU manufacturers collude to make sure every user gets it, whether they want it or not, so that when they start pushing remote-attestation and other user-hostile technologies in the future, they won't lose any market. > Mainstream phones run non-privileged I specifically said "non-rootable", i.e. non-privileged by default, but that can be unlocked. So mainstream phones would remain non-privileged except for those motivated enough to follow an unlock procedure. But it's a common tactic to excuse deliberate lock-down with "few need it, so we will invest resources into making sure they can't have it, when our previous models allowed it". If MS prevented users from running any compiler except Visual Studio on Windows, would you excuse it because those that need it are a niche market, for whom the more expensive Windows Pro licenses are made? > subsidized TV with more features sell better than more expensive TV with fewer features There are no non-smart TVs on store shelves next to smart ones, just for a higher price, despite demand [1]. In fact it's a challenge to find one at all. Saying it's just about money is technically correct in most cases, but very misleading. It hides the fact that in most cases it's not just about offering a cheaper product, but involves backroom lobbying from other interests to restrict consumer options, like forcing them to watch ads on DVDs [2]. It's "about money" in the same way that robbery is about money. [1] "This question of smart-TV data privacy and security is by far the most-asked among Ask Wirecutter readers." - https://news.ycombinator.com/item?id=35484594 https://news.ycombinator.com/item?id=35484594 [2] https://en.wikipedia.org/wiki/User_operation_prohibition https://en.wikipedia.org/wiki/User_operation_prohibition
- andai 3y ago>The telescreen received and transmitted simultaneously. Any sound that Winston made, above the level of a very low whisper, would be picked up by it, moreover, so long as he remained within the field of vision which the metal plaque commanded, he could be seen as well as heard. There was of course no way of knowing whether you were being watched at any given moment. How often, or on what system, the Thought Police plugged in on any individual wire was guesswork. It was even conceivable that they watched everybody all the time. But at any rate they could plug in your wire whenever they wanted to. You had to live--did live, from habit that became instinct--in the assumption that every sound you made was overheard, and, except in darkness, every movement scrutinized.
- 1827162 3y agoAnd that is precisely what using the Internet in 2023 entails. Every single thing you do is being monitored and compiled by the government. Likely with CloudFlare acting as the universal man-in-the-middle. https://theintercept.com/2015/09/25/gchq-radio-porn-spies-track-web-users-online-identities/ https://theintercept.com/2015/09/25/gchq-radio-porn-spies-tr... And you directly feel the chilling effect of it, no longer can you type whatever you want into that search box anymore. It's super creepy, and we're used to it. Only when it's gone, for example when we use a locally running AI chatbot, do we feel freedom again, and the difference is striking. Thank God the next great thing in tech is AI and we have the option of running that locally. And because of that, I am looking forward to tech progress again. Where progress doesn't always mean expanding state control over people.