Hacker News new | past | comments | ask | show | jobs | submit
> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.

That's a weird way of putting it. You'll basically need a second non-Linux device if you want to use Linux.

If your reason for using Linux is "I want to continue using old hardware instead of quickly-obsoleted devices", then you're shit outta luck: you'll have to buy a (potentially second) device from one of those vendors who'll use the profits to further lobby against your rights.

And it's not just desktop _linux_ that's not allowed, but any desktop operating system, since this only works with "smartphones" not general-purpose computers.

(and of course even if they were to support computers, an age/id verification system either won't work at all or only work to be abused by those in power)

> The project’s position is that hardware binding remains required

I think you're downplaying the real risk: if TPM becomes necessary for any single routine activity (banking, communication, etc.) then the usability of any non-TPM hardware to access the internet approaches zero. What's the point of a Linux desktop that asks for attestation for every HTTP request? Or an Android phone that can't legally allow you to install APKs from beyond the Play Store?

I can't pay for things with NFC on my GrapheneOS phone because my bank doesn't trust the hardware. While this is a slight annoyance, it doesn't meaningfully affect my ability to use cards or type in numbers or authenticate with a fingerprint on my phone; however, the forced use of TPM to access anything should be rejected and protested at every step.

Encryption can never be stamped out, thankfully, but hardware is not within one's control: you get what is allowed to be sold.

If you want to actually enforce age restrictions that can be checked via some kind of digital identity I don't see how we can avoid the "trusted" hardware requirement.

The key material must be DRM'ed, especially if some ZKP solution is used.

Otherwise all underage kids would download the cool older brothers private key and load it into their GNU Taler client, buy wine and be gateway'ed into heavier Stallmanisms. Before soon EMacs would be all the rage in highschool.

(Of course we can argue the bigger points, if X should require age checks, or if this even should be done digitally etc. But there's a reason why we don't allow the physical equivalent of self-signed keys for physical ID's, they're not trustworthy)

loading story #49149960
loading story #49149525
Xkcd 538. Hardware attestation is not required because it's not sufficient, you need to plug all the other much easier ways to get around the system.

Firstly, you need to comprehensively ban VPNs, probably with some great firewall setup.

Secondly, you need to install CCTV in people's homes to make sure that nobody uses someone else's device to get around the system.

Then it's time for hardware attestation.

loading story #49149874
We need to remember how to operate without the Internet, and de-risk our dependence on it. Whether that's reducing the use of computers in our daily lives, or getting more open-source-software-runs-offline-on-my-machine.

We did it before. We forgot at the time when things were more-or-less free.

(I don't know how we do this. I'm as dependent as ever.)

So much for the EU's mission to reduce e-waste.