523
submitted 1 year ago by mastermind@lemm.ee to c/privacy@lemmy.ml
you are viewing a single comment's thread
view the rest of the comments
[-] redezem@infosec.pub 11 points 1 year ago

Question for anyone with more understanding of the implementation…

Doesn’t this still presume the browser tells the truth to the third party attester? Could we not build something that just straight up lies to the attester? Says I’m a good Google chrome user with no extensions please serve me ads sir?

[-] koper@feddit.nl 1 points 1 year ago

This system would use cryptography and hardware to make sure that you are unable to lie about any of this. Basically, there is a chip inside your CPU that contains special keys installed by the manufacturer. However, this chip only activates itself when it detects that your device is running the approved software. Furthermore, it is made (almost) impossible to open this chip and retrieve the keys without destroying it.

[-] redezem@infosec.pub 2 points 1 year ago

I dunno man, you can virtualise tpms, and if you can virtualise it, you can lie about it.

[-] koper@feddit.nl 1 points 1 year ago

You can virtualize a TPM, but you can't obtain a valid endorsement key.

load more comments (1 replies)
this post was submitted on 26 Jul 2023
523 points (98.7% liked)

Privacy

31609 readers
219 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS