Elektrine lite

← Feed

@qqq@lemmy.world

Post #1792590

2026-04-22 14:05 UTC

Security is constantly used as a guise for removing consumer rights and as someone who has been in the security industry for about 9 years I’m so sick of it. First and foremost, everyone please understand: the user should be allowed to opt into your concept of insecurity: you do not know their threat model and you do not know their risk tolerance. Using exploits in low level drivers in the wild is approaching APT level, and even if there were a simple one to use it’d likely be useless without some sort or local access to the device (bar some horror show bug in a Bluetooth or WiFi firmware). The risk is incredibly low for the average person. I’d put it pretty close to 0. Wire transfers aren’t instant and for large sums (your inheritance) the banks will likely require more than just a request from your app. If the bank cares about that then they can also use the attestation APIs which would be more than sufficient, as much as I hate them. This boogey man of the APT going after my technologically illiterate with nation state level exploits needs to die. Long ago we entered a new era of security where it just isn’t worth it to waste exploits. Especially when you can just text people and ask for their bank account and that works plenty well. Security is not a valid reason to soft brick consumer devices at some arbitrary end of life date.

Replies (1)

  • @porcoesphino@mander.xyz 2026-04-22 14:36

    Agreed, but I think a framing or two is missing here, and it only applies to a subset, is that the people of the world shouldn't have to deal with more/larger bot nets because these things haven't been considered. Another is just that the average great aunt isn't *opting into a concept of insecurity* they're simply ignorant to what threats there are. If it's possible to distinguish between the two sets of people, or to maybe even bucket devices by potential threat, it might go a long away. I probably a lot wrong here, I just woke up. But yeah, agreed security is an argument that's hidden behind

    Open ##2093629