logoalt Hacker News

matheusmoreirayesterday at 11:34 PM1 replyview on HN

> Most analysts expect

Total bullshit.

There is no "effective" method without hardware remote attestation. If I control the system, I can just spoof whatever "verification" it is you're asking.

The whole point of hardware attestation is to put a cryptographic key in the computer that the users can't ever get at, then use that key to prove the computer booted a corporate owned operating system that's 100% aligned with government and capitalist surveillance and other cyberpunk dystopia nonsense.

Install a custom system that you control and they will say you have "tampered" with your device, and that transgression will get you ostracized from digital society.

This is what will happen, and if we let it happen might as well close down this site because everything the word hacker ever stood for will have been destroyed.


Replies

izacustoday at 12:02 AM

You can of course create an independent attestation database at any time and mandate its use - verifying that the custom OS you use fits minimum security requirements for digital ID use.

We use that approach in several other industries.

But.... that requires work beyond just complaining.

show 1 reply