Hacker News new | ask | show | jobs
by wibbily 541 days ago
I see this going in the opposite direction first - TPM-backed kernel level fingerprinting. Surely you have nothing to hide…
3 comments

This page only works on digitally signed supported operating systems. Please consider migrating to a supported system by Microsoft, Apple or an Android device officially supported by Google.
This is my conspiracy theory as to why Win11 made TPMs mandatory hardware.
Fingerprinting or attestation?
Attestation of working fingerprinting.
If you're running your workload on someone else's hardware (eg in the cloud) being able to attest it's not being modified is critical. From a companies perspective, when they run their software in the context of a customers hardware, it makes sense that they may similarly wish to ensure the software is running unmodified. This is how games are able to ensure there is no cheating occuring and banks can ensure malware is not tampering with the bank software unbeknownst to their customer. There are obviously ways for this to be use this for more distasteful mechanisms like fingerprinting, but that's not necessarily enough reason to abandon the technology. There are ways to achieve attestation without compromising privacy, but it does require widespread rollout of the attestation mechanism.