Forgot your password?
typodupeerror

Comment Re:Integral layer of the Trusted-Computing/DRM sta (Score 1) 34

Every time people hear what it actually involves is outrage and opposition, at least all the way back to when Intel first announced that they wanted to hardcode identity numbers inside CPUs in 1999. But the corporations involved have been relentless, and have sunk countless billions of dollars steadily forcing it forwards, and building front organizations to obfuscate and whitewash it.

With Windows 11, Microsoft was finally able to FORCE Trusted computing hardware into every new computer. Not just every new Windows computer, but every computer.

Every new Intel PC CPU has built in Trusted Computing enforcement hardware. Every new AMD PC CPU has built in Trusted Computing enforcement hardware. Every new ARM PC CPU has built in Trusted Computing enforcement hardware. The only processor lines that DON'T have it are the microcontrollers.

There are some unlocked smartphones available, but as far as I can determine it's literally impossible to buy a smartphone that doesn't have hardware trusted computing built in.

I specified that enforcing Trusted Computing at the internet access level is still a long term goal, they couldn't get away with it today. However they are well on the way to success. Virtually all new hardware supporting trusted computing, all the front groups rolling out standards and systems, and as it gets incorporated into things everyone is going to increasingly running into situations where they get locked out of stuff if they're not Trusted Computing compliant. Streaming already restricts you to the worst quality if you're not compliant, and it's only going to get worse as pre-Win11 computers fade out and as more things require it.

Comment Re:You think we won something? (Score 1) 128

You are entirely correct. I took another look at what the law actually required and I am definitely crying wolf (at this point). Thanks for taking the time to point this out to me.

There is definitely a slippery slope there, but I agree with you, California is far enough away from the event horizon of that slope that my histrionics are not warranted. Not only that, but the carve out for Linux actually is helpful. Thanks once again.

Comment Re:Dual purpose age-bracket signal :o (Score 1) 128

I'd hardly call exact date of birth "low information content".

And yes this does reveal exact date of birth, regardless of the bullshit obfuscation that it supposedly only reports age range. The server simply tracks the reported result every time the user connects, and on some specific day the result CHANGES to announce their date of birth.

-

Comment Integral layer of the Trusted-Computing/DRM stack (Score 1) 34

This is based on SLSA (Supply-chain Levels for Software Artifacts), brought to you by the same fuckers making Trusted Computing and the TMP (Trusted Platform Module). It's part of the same shitstack to prohibit you from altering your software and to lock you out of your own files, and to send spy reports out over the internet so you can be cut off if you "fail" the Trusted Computing check.

The software can use a TPM's (Trusted Platform Module) Sealing function to encrypt your data such that it's impossible to access your own data if the software is modified. It can then pass control over that data only to software updates that carry a signed security certificate from Broadcom (or any other company using this system).

It is no longer open source, your system no longer works as you can no longer access your Sealed data if you change so much as a single letter of the code. Even recompile unaltered code won't work, unless you magically manage to get your build environment absolutely identical to the company's build environment and get byte-for-byte output. Even that may be impossible with the newer levels of non-deterministic compiler optimizations.

Also, with TMP's Remote Attestation feature can be used to transmit your machine's software configuration over the internet, so that you can be cut off if your system doesn't match Broadcom (or other company's) cryptographically signed certificate.

And then of course there's Network Access Control (NAC) / Trusted Network Connect (TNC). In the long term, the goal is for ISPs to use NAC/TNC to interrogate your computer for Trusted Computing compliance, and deny you any internet access whatsoever if your machine isn't compliant. Software with this sort of "security" certificate would pass inspection, while any attempt to alter the code would be detected as "tampering". You then get "quarantined". What "quarantine" means is that you are denied internet access - with the exception that you do get very restricted access which can only be used to download the approved software to "fix" your computer into Trusted Computing compliance.

Comment Re:You think we won something? (Score 1) 128

The companies in question are going to get in serious legal trouble if they fail to comply in verifying the ages of their users. Microsoft, Google, and Apple are all going to give these companies an API that will move that burden from themselves to the makers of the operating system. Discord, to use an example, will be able to say that they asked Microsoft, Google, and Apple to verify ages, and then that they relied on the information that they were given. What's more these companies actually want to know the age of their users. This information is valuable, and they will be able to use it to target their customers with advertising.

What's more, every bad actor is going to try and target this exception. Linux traffic will end up in the same bucket as bots, predators, and any other malicious traffic. There is nothing in the current exception that requires companies to work with Free Software. My guess is that if your operating system can't do age verification that is blessed by Microsoft, Google, or Apple that most sites will simply block your traffic.

This is going to end up being a huge step backwards for Free Software clients.

Comment Re:Excellent (Score 1) 128

Social media sites are going to get in trouble if they can't verify ages, and they want the age information so that they can sell it to advertisers. Microsoft, Apple, and Google are going to create APIs that the various services are going to trust. If your alternative implementation of the API response isn't signed by a key controlled by Microsoft, Apple, or Google it will be blocked outright. This loophole is not a victory, it is a huge defeat.

These operations can get in actual legal trouble if they don't gather this information. Plus, it is in their best interests financially to gather this information. Verified age information is ridiculously valuable to them. They want to be able to get your verified age, and now they have a legal reason to require it. Plus, every bot, actual predator, and other bad actor is going to try and climb through this Free Software exemption. The overwhelming majority of traffic that can't provide a response signed with a key by Microsoft, Apple, or Google is going to be crap, pure and simple. This law doesn't say anything about requiring that the service work with Free Software. Instead it puts Free Software in its own little ghetto. One thing is certain about ghettos, they don't put you in a ghetto for any reason but to be able to discriminate against you.

It is far more likely that a year from now Linux will be unusable for sites that require age verification, than it is that Linux will be the loophole that websites allow ti work despite not having "certified" age verification. Microsoft, Apple, and Google didn't fight this because they know that this actually strengthens their grip on operating systems. From now on, any device created by people that want to potentially do business in California (ie, everyone), is going to have to find a way to get a "blessed" age verification API by one of the big three. If they can't get that blessing then their fancy new device is unlikely to work on any service that has personalized accounts.

Comment Re:You think we won something? (Score 3, Insightful) 128

The exception only gives websites and other software a way to break if you insist on using Free Software. Every malicious bot, every child predator, every last bad actor is going to pretend to be Free Software, and people needing to comply with the law are simply going to block everything that isn't made by Google, Microsoft, or Apple. The reason that this got through the legislature is that it is the opposite of a win for Free Software, it is a devastating loss.

The commercial software vendors are going to create a framework that is going to insist on software signed by one of them to be "legitimate," and everyone that needs this verification to meet the standards of the law is going to simply block traffic that doesn't provide it. Free Software will still technically be legal, but it won't interoperate, and so it won't be usable.

You can see a bit how this works with Google Chrome on Linux. It mostly works great, until you need to watch something that requires Widevine, and then it either doesn't work at all, or it works with artificially reduced functionality. This is not because Chrome on Linux is less secure, or less capable, but rather because it is different. This isn't stopping piracy, the streams still escape. In fact, there are streaming services that I don't pay for, despite wanting to watch their content, simply because I would have to boot into something besides Linux to use their service, and the extra work isn't worth the hassle.

The difference is that this law is going to cover essentially every service that we want to use on the Internet. Every website, every app, every service with accounts that wants to be able to do business in California (and that's basically everyone), is going to require this age verification. Not only are they going to get in trouble if they don't get this information, but they actively want the information so that they can use the information to sell to advertisers. These operations aren't going to work on a non-validated code path. They are simply going to require commercial software verification and block everything else. It is not only the path of least resistance, it is the path of greatest profit.

No where does the law require that services work equally well without age verification. No where does the law say that the standard has to be open and implementable by Free Software. The reason that this exception stayed in the final bill is that the commercial software vendors saw this and realized that if they were going to be forced to build this API they could at least use it as an opportunity to shoulder out their competition for the long term.

Heck, this doesn't just work against Free Software. It is going to work against any newcomer to the party. Anyone creating a new device is going to have to use negotiate to use software blessed by Microsoft, Apple, or Google, because website and application operators are going to be skeptical of anything else. Anything else is going to look like a bot, or an attack, or some other bad actor.

Comment Re:All that is old is now new again (Score 1) 24

The new system is simply another set of inputs. You will still get search results even if you don't click on anything. In fact, I would bet that actual user interaction with this new system is going to be very small. Most of the input that Google will get will be people trying to game the system.

Comment Re:Needs an official Linux boot camp (Score 1) 70

I wrote a compiler for an ObjC-like language (with less brackets), which can produce binaries for any of {Mac, Windows, Linux, WASM, Arm A9 (Zynq), m68k or 6502} running on any of {Mac, Windows, Linux}. So you can produce a dev-signed Mac binary on a Linux box. I’m just going through extending that output range to mobile {Android, iOS} and I’ll release it as open source.

The compiler docs for the language (xc) are at https://compile-xc.org/ - feel free to browse.

I didn’t think getting the signing working for Mac/iOS was terribly hard.

Comment Re: All that is old is now new again (Score 1) 24

That is a very good point. duckduckgo.com (to use an example) does not summarize the search results for you, and, once you know what to look for the ads are clearly marked. To be honest, purchasing ads on duckduckgo.com is likely a sign of good taste on the part of the advertiser as well. Honestly, I hadn't even considered using a non-Google search option for a long time. That is almost certainly part of the problem. Thanks for your response.

Comment Re:All that is old is now new again (Score 4, Informative) 24

There was nothing automatic about Google's trustworthiness. It simply counted up links that lead back to a particular page. If it had more links it was (supposedly) a better page. Almost immediately webmasters around the world started gaming the system. Google still restricts some of the things my account can do for hidden links that were added to some ads on websites that I ran in like 2001. GoDaddy and all of the other big web hosting companies of that era all rose to prominence on the strength of gaming the PageRank system.

I am sure that other industries tell the same story.

PageRank might seem trustworthy to you, but that's only because you weren't trying to game the system back in the day. I can assure you that, right from the start, people were abusing PageRank in precisely the same way that upsets you now. The only difference was that registering a domain back then cost $70 for two years, and you probably created the links you used to game the system by writing Perl. That raised the barrier to entry significantly. However, there was still real money to be made in that arena, and whether the winners paid Google directly, or paid for back links to their content (or both), I can guarantee you that the road to your trust was paved in money.

In the end Google has decided that the most reliable way to have publishers show that their information is trustworthy is to force them to pay for the privilege. Coincidentally that also happens to be the method that makes Google the most money. For years an entire SEO industry has thrived around the idea that if you pay someone enough money they can trick Google to steal your information instead of your competitors. Now we are finally at the endgame and Google doesn't even send traffic. They simply summarize the information for their customers. Chances are excellent that you don't even leave the google.com domain.

Google's competitors are simply doing the same thing at a different domain. All of them make their money by charging publishers to show up prominently in search ranks. Whether you are rooting for Oceania, Eurasia, or Eastasia it's Big Brother all of the way down.

Comment Re:attack (Score 4, Interesting) 66

City Council member of a non-listed Twin Cities suburb I know:

FBI is involved. Most water systems use one of two control/alert systems that are old and make them easy targets.

All they did was shut down components of the systems e.g., wells/sewer lift stations. Most cities were able to cycle manually to get back up and running. There was not messages warning or ransom of which I am aware.

They could have done a lot more damage if they wanted to, rather than just shutting things down.

Slashdot Top Deals

We're here to give you a computer, not a religion. - attributed to Bob Pariseau, at the introduction of the Amiga

Working...