Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> TPM-backed full-disk encryption is now generally available in the Ubuntu installer. By tying encryption to the TPM security chip, disk encryption is bound to a specific device, significantly raising the bar for physical access attacks while improving the user experience.

That's great, but they are also intending to comply with the OS-level age verification [1]. Initial implementations will somehow be privacy protecting, but eventually the temptation to tie a specific person to an OS fingerprint will become too great.

[1] https://www.reddit.com/r/LinusTechTips/comments/1rk4fj7/ubun...

 help



How long until I can selectively tell certain websites I'm a child so they stop showing me ads?

They wanted the personal computer to store and report personal information. I hope they have their best surprised faces ready for when computers report what the owner wants them to report.


That is only possible when you really are the owner. And the amount of device out there in the world where people really are the owner is rather small. (Just the Linux desktops and the GrapheneOS smartphones, etc.)

You are not quite the owner on GrapheneOS either, because of Android Key Attestation (which has functionality analogous to desktop TPMs). If you re-unlock your bootloader (say, to run a custom build of GrapheneOS), attestation will snitch on you and the subset of apps that use key attestation to require a locked bootloader and/or enforce an AVB key allowlist will not work properly. This is a very small subset of apps currently, but I don't see it getting any smaller.

GrapheneOS does everything and more for key attestation, allowing security sensitive applications to test the integrity of the device. Sadly some apps like google wallet not only check for attestation, but check if Google's signed it. Which is against the idea of attestation in the first place.

So google's tap to pay doesn't work, but others do, like garmin pay. Random bank apps are hit and miss.


> GrapheneOS does everything and more for key attestation

Right, that's the problem, in my opinion. I'm not referring to the apps that require Google's keys only, I'm referring to the ones that allow GrapheneOS keys too. If you use one of these apps, you can use vanilla GrapheneOS builds, but you cannot run your own self-signed builds.

You are gaining freedom relative to running Google's OS, but you are still not free to further modify the software running on your own device.

Apps that require "integrity" should monitor their own integrity only, they should not attempt to infer the integrity of their environment.


Trick is there's no integrity without the OS. Cheats can ruin games, keyloggers can record passwords, music/movies can be stolen, bitcoins can be stolen, etc.

Attestation does not solve this.

How so? Seems like it's a pretty big step in the right direction, sure an attested phone is going to be much harder to compromise than one with custom os, custom kernel, and a user with root.

You can never own a device with a cellular modem. They can all provide backdoor access regardless of the primary OS.

It is possible to build a device where the modem is not at all trusted, but I don't know if anyone is actually doing that.

Librem 5 has a removable modem on M.2 card. Would this count?

The fewer devices doing it, the more effective it will be for those who do it.

Dont ask permission.

Run firefox with Ublock Origin and all blocks turned on. Add Sponsorblock to block in-video sponsor crap on Youtube.

Run Bypass Paywalls Clean from https://gitflic.ru/project/magnolia1234/bpc_uploads


Is there a good combo that works with spotify web?

I will never feel bad about blocking ads on youtube, because they have an effective monopoly on distribution of certain content. But when it comes to music, why not just use something else?

I recommend buying your own CDs (at your local music store, directly from the band when you attend their concerts, or on Bandcamp/Discogs), ripping them, and putting them on the local file system of your MP3 player, phone, your car’s SD card, etc. Sometimes if you buy a vinyl record it comes with a convenient download code, and if it doesn’t digital albums are very cheap on Bandcamp.

I also recommend tuning regularly onto your favorite radio station (mine is KEXP Seattle; and Rás 2 in Iceland) particularly when they have live performance to discover new music.


Piracy.

I have been experimenting with self hosting Navidrome for that purpose.


And as always, it deserves to be stressed that Sponsorblock is far more than the name suggests. It can also skip sections like intros, tangents, etc - and it's configurable per channel.

If you're listening to a music playlist on YouTube, this removes interruptions caused by the pointless intro and outro screens added to songs.


How is that even remotely related?

The Linux implementation I've seen is the Freedesktop implementation that just responds to a user profile flag. There's no cryptography involved, it's just like asking for a room number like the adduser command does.

Edit: well except American states don't flag your operating system as illegal unless they ask for your room number. Canonical and all the other Linux companies really like being able to make money and not spend all of their earnings on lawyers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: