Live data from Hacker News

Brave New Trusted Boot World

0pointer.net

31–40 of 178 posts

Re: Brave New Trusted Boot World

#31
post #12
post #10

Earlier quoted context omitted.

>This isn't about your own private machine. This is about corporation-owned machines in an enterprise network and as we see with nearly biweekly news articles about large-scale ransomware attacks, private data leaks and compromised employee machines, I would argue that the currently employed solutions clearly don't work. The fundamental issue is that you can't have one without the other, and that's bothering me. It's…

> you can't have one without the other, AFAIK, secure boot can be disabled, both in the BIOS and in the Kernel. In some machines that's not be the case due to contracts with Microsoft, but those already can't run Linux in the first place, so you probably won't buy them for the purpose of running Linux. The suggestions in the original post do not change anything about this.

The thing is a lot of machines get a second life running Linux. So these controls will end up making that hardware less useful in the longer run.

Re: Brave New Trusted Boot World

#32
post #24

I'm OK with making sure the software I'm running is the software I thought I was running. But because trusted boot runs so deep, and is intentionally hard to get around, it's vital that the implementation is trustworthy. I don't trust Poetteringware. Poettering's team has a record of foisting technology on users, resulting in the need for e.g. the Devuan fork. I wish this work were being done by just about any other…

> I don't trust Poetteringware. Poettering's team has a record of foisting technology on users, resulting in the need for e.g. the Devuan fork. They have been developing software, that enough people have deemed useful to include it in their distributions. Some have disagreed, and have made other choices. No one was forced to do anything, there have been no "foisting" and the "need" for Devuan is a subjective opinion.…

> There is really no need to transform purely technical arguments into personal attacks. This just discourages participating into free software development.

While I agree with you in general, for some reason this particular developer tends to take decisions that have very extensive consequences and make choice extremely difficult.

Re: Brave New Trusted Boot World

#33

As somone who never really viewed systemd as a problem I'm starting to think the systemd "haters" were actually right, at least somewhat... Viewing Poettering as some kind malicious entity undermining projects sounds like a conspiracy theory. But now with him working for Microsoft his actions do look like a lot like the "embrace, extend, and extinguish" pattern to me. Yes, yes "Microsoft And now I am supposed to chee…

I always thought this outcome was obvious. Systemd controls everything that happens before Linux boots. It controls everything that happens after Linux boots. Might as well call it GNU/Systemd at this point. It's the silent revolution no one wanted. The name itself implies a manifest destiny because System D is 100x greater than System V and they intentionally break POSIX compliance too. Now that the guy who owns the systemd project works for Microsoft, in addition to the fact that the Linux kernel now needs to be a Windows executable in order to boot, that really tells you all you need to know.

Re: Brave New Trusted Boot World

#34
post #24

Earlier quoted context omitted.

> I don't trust Poetteringware. Poettering's team has a record of foisting technology on users, resulting in the need for e.g. the Devuan fork. They have been developing software, that enough people have deemed useful to include it in their distributions. Some have disagreed, and have made other choices. No one was forced to do anything, there have been no "foisting" and the "need" for Devuan is a subjective opinion.…

> There is really no need to transform purely technical arguments into personal attacks. This just discourages participating into free software development. While I agree with you in general, for some reason this particular developer tends to take decisions that have very extensive consequences and make choice extremely difficult.

A developer that has been able to make tough choices and drive them well enough to get mass adoption?

He definitely isn't perfect but this sounds like quite the feat in Open Source.

Re: Brave New Trusted Boot World

#35

I'm OK with making sure the software I'm running is the software I thought I was running. But because trusted boot runs so deep, and is intentionally hard to get around, it's vital that the implementation is trustworthy. I don't trust Poetteringware. Poettering's team has a record of foisting technology on users, resulting in the need for e.g. the Devuan fork. I wish this work were being done by just about any other…

Going back to the init.d clusterfuck is insane.

Re: Brave New Trusted Boot World

#36
post #28

Earlier quoted context omitted.

What are, if any, "advantages of remote attestation" besides enforcing DRMs and preventing sideloading/jailbreaking? Preventing those who need access to proprietary systems from using any distro except 1-2 certified ones?

So that you can be confident that your software hosted with a random cloud provider has been faithfully launched? This is why Intel is keeping SGX in their Xeon processors despite killing it off in consumer oriented series--servers benefit greatly from the ability to prove to clients that they are well behaved

I will never be confident, only the hoster's reputation of being competent and benevolent can matter. Nevertheless I appreciate the clue, thank you.

Re: Brave New Trusted Boot World

#37

As somone who never really viewed systemd as a problem I'm starting to think the systemd "haters" were actually right, at least somewhat... Viewing Poettering as some kind malicious entity undermining projects sounds like a conspiracy theory. But now with him working for Microsoft his actions do look like a lot like the "embrace, extend, and extinguish" pattern to me. Yes, yes "Microsoft And now I am supposed to chee…

This stuff predates poettering. If distros are going to support encrypted rootfs boot then it's better it is actually secure then... in the end locks are neutral so long as the locks on your stuff only accept keys you control.

Re: Brave New Trusted Boot World

#38
post #16
post #12

Earlier quoted context omitted.

> you can't have one without the other, AFAIK, secure boot can be disabled, both in the BIOS and in the Kernel. In some machines that's not be the case due to contracts with Microsoft, but those already can't run Linux in the first place, so you probably won't buy them for the purpose of running Linux. The suggestions in the original post do not change anything about this.

I am mainly worried about remote attestation encroaching on territory which was traditionally under the user's control. And once this tech reaches critical mass, sure you can disable it however that also means turning your machine into a glorified paperweight that can't access anything arbitrary websites and software.

You see this on Android, my banking app requires that it is running an OS approved by a big vendor. Their website, especially the mobile version, is getting more and more tedious to use.

I want to be able to access all services with whatever client I please. Not be required to run approved software and hardware that puts them in control.

Re: Brave New Trusted Boot World

#39
post #33

As somone who never really viewed systemd as a problem I'm starting to think the systemd "haters" were actually right, at least somewhat... Viewing Poettering as some kind malicious entity undermining projects sounds like a conspiracy theory. But now with him working for Microsoft his actions do look like a lot like the "embrace, extend, and extinguish" pattern to me. Yes, yes "Microsoft And now I am supposed to chee…

I always thought this outcome was obvious. Systemd controls everything that happens before Linux boots. It controls everything that happens after Linux boots. Might as well call it GNU/Systemd at this point. It's the silent revolution no one wanted. The name itself implies a manifest destiny because System D is 100x greater than System V and they intentionally break POSIX compliance too. Now that the guy who owns the…

No-one's making you use it. Choose a distro that doesn't package it - there's plenty to choose from.

Re: Brave New Trusted Boot World

#40

Earlier quoted context omitted.

> There is really no need to transform purely technical arguments into personal attacks. This just discourages participating into free software development. While I agree with you in general, for some reason this particular developer tends to take decisions that have very extensive consequences and make choice extremely difficult.

A developer that has been able to make tough choices and drive them well enough to get mass adoption? He definitely isn't perfect but this sounds like quite the feat in Open Source.

There is a huge difference between a developer who creates a superior project that everybody loves to use so it gets mass adoption and one who makes a product that gets pushed by their employer on everyone whether they want it or not. I don't want to get into details as the subject has been beaten to death but as for Systemd* there was the case of integration with graphical login that made choice difficult. Had the author been more sensitive to this issue and cooperated a bit without being stubborn we wouldn't have had Devuan and all that mess. This is exactly NOT the way to do things in open source.

*PulseAudio was simply broken but it's not the fault of the author distros picked up aplha-quality software

Post reply on HN