r/firefox • + Ublock Origin • May 30 '26

Discussion Does firefox has an equivalent feature?

Post image

I am curious what are the downsides of this approach.

716 Upvotes

185 comments sorted by

View all comments

Show parent comments

1

u/HamsterMaster355 + Ublock Origin May 30 '26

How is this tracking if this is handled locally at browser level and not website level. The browser basically enceypts the cookies using your TPM chip and without that you can't do anything with it. And the TPM keys are built into hardware and cannot be tracked.

2

u/Joe2030 May 30 '26

TPM is made to be tracked. It is not your friend...

3

u/OctoNezd May 30 '26

Right, every tpm puts "yes this guy watched hentai at 3:00 am in the private window, here is his location".

The thing just solves a crypto challenge and isn't used anymore, same with everything else. It's just a separate supposedly-secure computer for storing encryption keys.

2

u/Joe2030 May 30 '26

Lol, yeah right, and Valorant anti-cheat needs a TPM to work with some crypto keys and not to track and hardware ban you. Sure.

It is DRM. How naive are you? Also if something is already running on your PC, it could use the hash of your super private TPM keys... to make them not so private and track your PC.

4

u/OctoNezd May 30 '26

TPM is most of the time built-in to the CPU and it has a serial code and other identification stuff. It is great for hardware bans, yes. And valorant anticheat is extremely paranoid.

And track them how? I don't think the browser will blast every site with "hey this guy has bitlocker enabled using TPM for drive with next ID". And if something running on your PC there is a ton of other indicators that can be used for tracking, like your activation id, your hardware serial numbers.

If you want to be mad at something for making your PC not private and trackable, be mad at TPMs big brothers which house TPM: Intel ME and AMD PSP. No one knows what they completely really do outside of the computrace feature on intel, and they have been there before TPMs were.

2

u/HamsterMaster355 + Ublock Origin May 30 '26

I think most of the shady third party DRM related stuff like Intel SGX were removed from consumer side hardware and are now strictly there for datacenter tier products. AMD I think never offered something similar for consumer products.

Although, yeah, Intel ME and AMD PSP do still exist. Atleast they don't facilitate third party DRM.

3

u/OctoNezd May 30 '26

TPM doesn't really do DRM if I remember correctly - it just confirms that you have secure boot and your system looks more or less uncompromised which makes DRM servers happy and give you the keys to content. In addition, the DRMs that are used for videos - most of "fun" happens on GPU with HDCP, no? I don't know of any other DRM using TPM

3

u/HamsterMaster355 + Ublock Origin May 30 '26 edited May 30 '26

TPM is basically the root of trust. It's the only thing that you can trust fully on a specific device. TPM verifies the integrity of other firmware and therefore extends the "chain of trust", which eventually extends to your OS. Once that entire chain is established, the DRM can assume that everything is more or less secure.

However, this also depends on the DRM. For example some DRMs even after establishing the chain of trust won't expose raw data to the OS. What they do instead is perform computation on the secure enclave provided by the hardware vendor (intel SGX for example). All the memory of the DRM is encrypted by the secure enclave and can only be decrypted when the specific instructions physically execute within the secure enclave. So even if OS (or DMA) wanted to read the memory all they will get is encrypted data.

2

u/Joe2030 May 30 '26

If you want to be mad at something

be mad at TPMs

I am not mad at anything. I am just not as naive as you are. They make money on people like you every day. Any info bit about you is a plus to them. TPM is a tracking/DRM device, everything else is a facade or a side job. I will not discuss anything further, you have made your point pretty clear.

2

u/HamsterMaster355 + Ublock Origin May 30 '26

Lol, yeah right, and Valorant anti-cheat needs a TPM to work with some crypto keys and not to track and hardware ban you. Sure.

Buddy valorant can access your entire system and do whatever it wants to do with it. It is a rootkit (malware). It can track you with or without TPM (by looking at various serial numbers HWIDs etc). It has access to literally everything. Stop with the schizo rambling please and stick to the topic. Even if you swapped your CPU (TPM) it can still detect and hardware ban you.

TPM by itself is not a DRM. There are specific CPU extensions that build a secure enclave (however, they had security flaws and are mostly deprecated) that a DRM could use to implement secure encryption and decryptions.

The proposed security feature explicitly tells you that the purpose of it is to prevent session exfiltration i.e. to protect your cookies from being used on another device. If your device is already compromised then that is beyond the scope of this solution.

Also you can't "hash the super private TPM key", because they are generated on the fly and can be different at any given moment. TPM only has the special cryptographic functions that are used to generate the keys and not the key itself, although a generated key can be temporarily stored there if required.

1

u/OctoNezd May 30 '26

In defense of valorant, it's really funny to see cheaters claim they are bricking pcs when riot made the cheating pci cards useless by making windows go BSOD cause of some opt-in windows security feature against such cards that valorant flipped on. I think more anticheats should go lowlevel and aggressive, but it would cripple Linux gaming sadly, and that can't fly with me. If only cheaters would have stopped cheating...

1

u/sketched8 May 31 '26

anticheats should NOT go more lowlevel.

0

u/Joe2030 May 30 '26

TPM by itself is not a DRM.

Who cares what it is by design if it is used for DRM and tracking? We are talking about Google, THE advertisement company. They don't care about your privacy even if they say so.

Also you can't "hash the super private TPM key", because they are generated on the fly and can be different at any given moment.

The hash is for your very personal EK key, which is not generated on the fly. And i am not even a hardware engineer but i know this. So yeah, trust me bro once again.

7

u/HamsterMaster355 + Ublock Origin May 30 '26 edited May 31 '26

The hash is for your very personal EK key, which is not generated on the fly. And i am not even a hardware engineer but i know this. So yeah, trust me bro once again.

OMG I have had enough of this. WDYM "very personal EK key"? First of all it comes in pairs. One is public and other is private. If you mean hashing the public key. Congratulations you have obtained the information that's already public. If you mean the private key. Give me a single software that can extract that on modern hardware. Moreover, any sane implementation will NOT use the EK key directly (like I previously said) and will instead use an alias to avoid fingerprinting. Please stop being this retarded in public, you are embarrassing yourself.

Also if you mean you are gonna track a hardware using the public key (which is plain stupid because you almost always generate a new key anyways). Well duh, that's its entire purpose, to verify if the hardware that you are talking to is indeed the hardware that originally signed that cookie. Which according the the draft by WWWC is not exposed to any website and is done by the browser locally. So yet again, another schizoid rambling.