HN user

gclawes

367 karma

[ my public key: https://keybase.io/gclawes; my proof: https://keybase.io/gclawes/sigs/g5Of9DRhZsqj-LL2Etz8VQ9sZ13dQYyHNgdPFmKkdQk ]

Posts0
Comments116
View on HN
No posts found.

Don't Windows Hello camera devices have some kind of hardware attestation? I'm sure verification schemes like this will eventually go down that path soon.

My guess is that's probably one of the reasons Google tried to push for Play Store only apps, provide a measurable/verifiable software chain for stuff like this.

I think drumming up interest in getting users to run Linux on frameworks is a way for them to go back to vendors and try to get them to fix issues like power consumption that bugs the hell out of users (looking at you AMD)

It's not really that a digital ID can be used to spy on people (governments can already do this to a pretty large degree without needing spyware). It's that it's a permission system that can be instantly updated and centrally managed by people that have legal authority to spy on you.

If your digital ID is controlled centrally by the government (the guys that are watching most things you do already), and you need your digital ID to do most commercial interactions (banking, buying things, travel, etc), it means the government can revoke your ability to do any of those commercial interactions (or even other things that aren't strictly commercial, think "travel papers" for driving out of state).

And it doesn't even have to be in response to criminal actions. You too too many trips this year? Well, you've used up your CO2 budget as a citizen, have fun not buying CO2-intensive food (meat). Said something racist online? Well we certainly can't let a person like you buy a car now, can we?

And yes, things like credit cards and credit scores are centrally managed to a degree, and Visa/Mastercard can deny transactions for somewhat-arbitrary reasons (they're actually fairly legally limited in how they can do this, it's not totally arbitrary). But these things are not tied into every aspect of your life (your bank doesn't necessarily know how many miles you've driven this year), whereas states can (or can invent the legal authority to) tie a digital ID into everything.

This is laying the groundwork for mandatory software. Soon after this browsers and messengers will be required to install tracking components to be included in the app stores or approved for sideloading.

This is how the surveillance blob will get around the huge backlash to Apple's mandatory on-device child abuse scanning, close off any avenues to escape it before re-introducing mandatory on-device spying.

Worse, surveillance appliances. Highly likely we'll see mandatory client-side scanning apps in EU soon, and possibly Digital ID stuff in the UK.

Great opportunity for mandatory remote attestation and mandatory software.

Tin foil hat time: this is why Google is pushing to kill app sideloading.

Mobile phones are the only platform at the moment that can reasonably be used to enforce mandatory software installs and remote attestation. Removing sideloading can down the road leading to Google (or Apple for IOS) forcing all app store provided apps/browsers to support government authentication APIs like this.