logoalt Hacker News

notepad0x90yesterday at 8:59 PM3 repliesview on HN

I just wish more people would protest this instead of things like secure boot.

Password managers and/or operating systems can manage private keys just fine. websites shouldn't be concerned with how the keys are managed, or be able to make demands on how users store credentials, or know device details for users.

One thing I dislike even with systems like FIDO2 is that the websites/apps can block list your FIDO key's vendors. Similar trends suck. Passkeys are just one iteration in a long line of systems designed with corporate interests in mind.

The system validating the authentication needs only to verify that the credentials are correct. If users want to use TPMs, HSMs,etc.. or none at all, that's up to them. And no information, other than what is strictly required to verify the credential should be transmitted over the network. a signature of challenge data from the app should be sufficient. the user's public key shouldn't be signed at all by hardware, a trusted 3rd party,etc.. the registration process should take care of establishing public key trust to the authenticator/app. The whole thing feels insidious.


Replies

dgxyzyesterday at 11:05 PM

Oh that's not even the worst of the stupid shit.

When you have Apple managing your keychain, your passwords stored in that, your passkeys stored in that, them filling in your MFA info by reading your email and SMS on every device, supplying your primary email account and all your throwaway addresses, and possibly trying to tie you into their OAuth or whatever for a third party, you are fucked if something goes trivially wrong.

digiownyesterday at 9:11 PM

Corporate interests HATE general purpose computing, and the freedom to run what you want. With that freedom, you can hurt their interests by blocking ads, stripping out spyware, or avoiding giving up your privacy, and they can't let you have that.

It's a death by thousand cuts that's finally starting to come together:

- Remote attestation like Play "integrity"

- Hardware backed DRM like Widevine

- No full access to filesystem on Android, and no access to filesystem at all on iOS

- No ability to run your own programs at all on iOS without Apple's permission.

- "Secure" boot on Android and iOS that do not allow running your own software

Ever wondered why Windows 11 have a TPM requirement? No, it's not just planned obsolescence.

If they get their way, user-owned computers running free software will never be usable again, and we'll lose the final escape hatch slowing down the enshittification of computers. The only hope we have is that they turn up the temperature a little too quickly that normies would catch on before it gets far enough.

show 1 reply
jmclnxyesterday at 9:24 PM

I fully agree, seems Linux is heading directly towards being a Windows Clone. So far all the windows crap can be easily avoided, but once these things are forced on me, it is bye bye Linux.

Already I use BSD on an older laptop probably 40% of the time. Linux on my main system is there due to a hardware device issue BSD still have a minor problem with it. But for me right now, Linux seems to be heading in a wrong direction.

show 1 reply