Damus
Taggart :ifin: · 3w
TPMs: exist Hardware attestation: exists MFA: exists Every package repo and cloud service: Yo let's put one-factor access credentials in plaintext inside our working folder. We gotta start using th...
Dave Wilburn :donor: profile picture
@nprofile1q...

TPM and hardware attestation is pretty darned flaky on a lot of platforms. That's especially true for anyone running unconventional OSes and/or jailbroken platforms outside of the strict control of the major oligopolies (MS, Google, Apple), and disproportionately the case for people most likely to be developers.

A lot of this stuff is also automated in a way that makes MFA fundamentally more difficult. Not impossible, just more difficult.

Do I think this is a valid excuse for maintaining the demonstrably unsustainable status quo through intentional neglect? Absolutely not. But the otherwise obvious solutions are pretty tricky for a lot of use cases.
1
Dave Wilburn :donor: · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq7yf7cxzxz4kwf24zmflvyqqtrylsjwm5q9a074u5ger57rmzz0aqe544dh It's also worth appreciating how all of these issues are cropping up at precisely the same time that all of our worst fears surrounding TPM and hardware attestation are coming true. I...