4 ms·
You can run a software TPM if you browse within a VM.
by Vecr 1y ago
You can run a software TPM if you browse within a VM.
- IlikeKitties 1y agoAnd that Software TPM has whos vendor endorsement keys exactly? Ah yes, ones that google won't consider valid.
- gjsman-1000 1y agoWell, it's a good thing Device Bound Session Credentials (DBSC) as proposed here has no way to actually send said endorsement key anywhere; rending the objection irrelevant. The TPM is only for secure storage as verified by the browser itself, not the website being visited.
- IlikeKitties 1y ago[flagged]
- gjsman-1000 1y ago> You all don't understand how any of this tech works but you think you do. We do; and it is specifically called out in the spec that the certificate chain is not submitted, due to the potential for overpowered fingerprinting. As such, this battle, should they make a move to change that, needs to be fought a different day. Fighting against hypotheticals is pointless. Edit: For the pedantic, fighting against hypothetical things that they could do if they invented something that doesn't exist right now, is pointless. Edit 2: You can't boil a frog without ecosystem cooperation. The internet isn't going to bow to inconsistent adoption. They already made it clear with WEI they have no interest.
- pessimizer 1y ago> Fighting against hypotheticals is pointless. No, fighting against things that have already happened is pointless. We only ever fight against hypotheticals. We fight to avoid something happening that has not happened.
- IlikeKitties 1y ago[flagged]
- kbaker 1y ago~~~~But your VM TPM won't be signed during manufacturing by a trusted root. No attestation.~~~~ OK I take it back, privacy is one of their specified goals: > Note that the certificate chain for the TPM is never sent to the server. This would allow very precise device fingerprinting, contrary to our privacy goals. Servers will only be able to confirm that the browser still has access to the corresponding private key. However I still wonder why they don't have TLS try and always create a client certificate per endpoint to proactively register on the server side? Seems like this would accomplish a similar goal?
- IlikeKitties 1y ago[flagged]
- gjsman-1000 1y agoDude; please stop spamming misinformation, this was already debunked in previous commentary you saw and responded to, showing that the website never sees the raw TPM data at any stage under this proposal. Session cookies have zero correlation to fingerprinting.
- arnarbi 1y ago> why they don't have TLS try and always create a client certificate per endpoint to proactively register on the server side That is effectively what Token Binding does. That was unfortunately difficult to deploy because the auth stack can be far removed from TLS termination, providing consistency on the client side to avoid frequent sign outs was very difficult, and (benign) client side TLS proxies are a fairly common thing. Some more on this in the explainer: https://github.com/w3c/webappsec-dbsc#what-makes-device-bound-session-credentials-different https://github.com/w3c/webappsec-dbsc#what-makes-device-boun...