Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Avamander
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
91.
▲
by
Avamander
6mo ago
> You can attest that cryptographic key material is safely stored without attesting that their operating system and software running on it is all government-approved. There's no proper way of doing so on Android. Some countries, lik
92.
▲
by
Avamander
6mo ago
> what you quoted was about the user getting informed whether their system is compromised, which is the job of a secure boot chain User being informed means they have to know what a compromised system would entail. That alone is a huge a
93.
▲
by
Avamander
6mo ago
Now you can't bundle malware deep within the system "ROM" unless you want to break SafetyNet's attestation. It's a big change in that aspect.
94.
▲
by
Avamander
6mo ago
> It's not that important to be able to do that. You have been educated to trade your freedom for that kind of convenience, but it is not necessary. It's important enough that people do so without any eID, using methods both mo
95.
▲
by
Avamander
6mo ago
We have had a large discovery of pre-installed malware every year for the past decade so far. Seems like a fairly big problem.
96.
▲
by
Avamander
6mo ago
One important feature of a legal ID is that it's hard to copy, so attestation from the hardware storage would have to be basically mandatory. But yeah, the user could have a choice to this extent.
97.
▲
by
Avamander
6mo ago
> If only currently popular platforms are to be supported, how could a new platform join them in the future if the use of existing ones is mandated by governments? The viable solution for that is to provide a trusted hardware implementat
98.
▲
by
Avamander
6mo ago
> Agree on Smart-ID but the answer is to fix those flaws Fundamentally can't be, it'd be a whole new solution. > For eSIM to support that use case, political will only is needed: the EU got Apple to abandon the lightning cab
99.
▲
by
Avamander
6mo ago
> but somehow we don't go and ban kitchen knives, as having them around is valuable Some countries do :) Though I think physical analogies are misleading in a lot of ways here. > Systems can be secure and trusted by the user with
100.
▲
by
Avamander
6mo ago
> The less stupid variant is, of course, to get mobile operators to issue SIM cards with e-sign capabilities. Estonia has that, for example: https://www.id.ee/en/mobile-id/ It works great. Just keep in mind tha
101.
▲
by
Avamander
6mo ago
Plenty of EU countries have rolled out SmartCards for this exact purpose, some are now adding NFC functionality. Nothing really stops Germany from continuing like that either. The issue then becomes the UI/UX. If the legal mandate is n
102.
▲
by
Avamander
6mo ago
Once SafetyNet was brought to Android a decade ago the tendency has been clear - these freedoms are going to be restricted heavily. Because how do you make sure it's the user who does those modifications, willingly and well-informed? T
103.
▲
by
Avamander
6mo ago
> The ability for us as users to lie to the apps is actually essential to preserving our agency. Without that we're screwed, as now to connect ourselves to the fabric of the society we'll need to find and exploit vulnerabilitie
104.
▲
by
Avamander
6mo ago
> because card reader support is still shit in browsers in 2026. Tragedy of the commons, nobody seems to have bothered to work on it. It's not like Chromium or Firefox wouldn't accept contributions.
105.
▲
by
Avamander
6mo ago
You keep lashing out at people in this thread. Demanding full control over something like an ID will fundamentally not happen. The same way you won't have full control over the way passports or paper bills are made. Take for example th
106.
▲
by
Avamander
6mo ago
SIM-based solutions are on their way out because phones are starting to lose SIM slots. Certifying eSIM implementations to the same EAL level (as Mobile-ID SIMs are) is way way too difficult. At least for one country doing it alone. Smart-I
107.
▲
by
Avamander
6mo ago
Indeed, the text feels very LLM-written.
108.
▲
by
Avamander
7mo ago
They can turn those knobs anyway, you need something like Secure Boot and measured boot to ensure an untampered environment. Simple encryption doesn't provide this. An attacker can just as well replace your GRUB. An encrypted boot part
109.
▲
by
Avamander
7mo ago
It would first require a standard for Markdown. After that there would be very little stopping anyone from implementing it. I guess a MIME type for standard Markdown would also be nice. Pretty sure I've said it before, but it would be
110.
▲
by
Avamander
7mo ago
In theory format=flowed solves that, but the same boomers that despise HTML mail also refuse to provide that accommodation, for anyone not behind a teletype.
111.
▲
by
Avamander
7mo ago
I'd start by not using self-immolating wires (hardcoded default passwords). Jokes aside, there's so much low-hanging fruit in IoT it's utterly ridiculous. Having any standards at all would be an improvement.
112.
▲
by
Avamander
7mo ago
> I’d rather have a local web archive of my tabs in my browser so that I can see what the website was like when I last saw it I'd start by having an option for a significantly longer browsing history. Just having an usable history s
113.
▲
by
Avamander
7mo ago
I truly despise the few recent generations of laptops vendors like Lenovo has put out. Plastic clips instead or (or in addition to) screws, flimsy on-board connectors, plastic bottom covers. At the same time the thermals are still horrible
114.
▲
by
Avamander
7mo ago
> A recent LinkedIn post that I came across as an example of people trusting (or learning to trust) AI too much while not realizing that it can make up numbers too Honestly, people make them up just as much or generate equally incorrect
115.
▲
by
Avamander
7mo ago
> Especially in JavaScript where I often share a lot of code between the client and the server and therefore also transfer data between them, I like to strictly separate data from logic Which makes me wonder how it'll look like when
116.
▲
by
Avamander
7mo ago
You take it too personally and if anyone is angry it's you. Listing shortcomings of a project is not "attacking", it's juvenile to think so. Shortcomings you refused to admit and your "explanations" were fundam
117.
▲
by
Avamander
7mo ago
They also have an overly reactive social media presence, somewhat similar to what ffmpeg has. Could end up being bad PR for Motorola. Funnily enough that same social media person has some odd ideas about trust and PKIs.
118.
▲
by
Avamander
7mo ago
Yes?
119.
▲
by
Avamander
7mo ago
I'm not sure it's even ethics, it might just also be about misaligned LLMs giving worse outputs and they don't want to make their models worse. Plus their models tend to be the least sycophantic and push back on inane stuff,
120.
▲
by
Avamander
7mo ago
Except anything that requires any non-trivial networking or hermetic building.
More ›