4 ms·
It reduces control of my computer because without it my computer can identify itself to websites and advertisers in the way that I want, but with it, it can onl
by zuminator 3y ago
It reduces control of my computer because without it my computer can identify itself to websites and advertisers in the way that I want, but with it, it can only use its TPM assigned identity. You can argue (I'd disagree) that it's a good thing that I can't make my computer spoof as something else, but unquestionably it does reduce my control.
- endisneigh 3y agoThis is wrong though. Wei doesn’t stop your ability to spoof, it stops your ability to be successful in spoofing.
- wilsonnb3 3y ago> unquestionably it does reduce my control It doesn't reduce your control, you are still welcome to identify your computer however you want to websites by using a browser without WEI or disabling it. You will just have to live with the reality that a lot of servers aren't going to want to talk to your client.
- wpietri 3y agoTheir point is that a browser with WEI reduces your control versus a browser without WEI. I would agree with them that it's definitional.
- dns_snek 3y agoThis is always such a bad faith argument. When you have to choose between freedom/privacy and being able to perform daily tasks, that's not a choice, but coercion.
- semi 3y agothe better argument is just flipping the perspective. if your computer runs a web server this increase the control because without it other computers can connect to it and lie about their identity. that's not to say I think this is a good thing, I just don't think control over your computer is a good argument when both sides of a connection are computers, and both operators want not just control over their computer but also what the other computer can do.
- zuminator 3y agoThat's fair, but it seems to me they could've done it differently -- require a signature from the clients but allow them to produce an unbounded number of valid unique signatures that are securely but anonymously tied to the client TPM. In other words the client would still be able to present a validated anonymized identity, but would not be able to generate someone else's signatures, and private-key-based revocation could still be available to deal with rogue TPMs.
- ToValueFunfetti 3y ago>without it other computers can [...] lie about their identity That's the point, I think. I own my computer, which means I decide whether it lies. If I want to serve "This website only works in Chrome" when it's actually cross-platform, that's my right. I might want the client to open the page in Chrome automatically, and I would have more control over the connection if I could do so, but that control would be over the client's computer. It's not a question of getting more or less control in general, but of getting rightful control over my own property. > both operators want not just control over their computer but also what the other computer can do Are you saying that my demand to not have a server control what my client does is an act of control over what their computer does? Like if I told you not to use your forklift to take my stuff, I'm asserting power over your property?
- semi 3y ago> >without it other computers can [...] lie about their identity > Are you saying that my demand to not have a server control what my client does is an act of control over what their computer does? Yes. The owner of that computer does not want to serve your requests and you want to prevent them from exerting that control over their computer. >Like if I told you not to use your forklift to take my stuff, I'm asserting power over your property? Yes that is what is being argued here. Forklift owners demanding the right to lie about using a forklift to property owners like Google who do not want to allow forklifts to take their stuff.