Earlier quoted context omitted.
>This isn't about your own private machine. This is about corporation-owned machines in an enterprise network and as we see with nearly biweekly news articles about large-scale ransomware attacks, private data leaks and compromised employee machines, I would argue that the currently employed solutions clearly don't work. The fundamental issue is that you can't have one without the other, and that's bothering me. It's…
> you can't have one without the other, AFAIK, secure boot can be disabled, both in the BIOS and in the Kernel. In some machines that's not be the case due to contracts with Microsoft, but those already can't run Linux in the first place, so you probably won't buy them for the purpose of running Linux. The suggestions in the original post do not change anything about this.
Brave New Trusted Boot World
31–40 of 178 posts
Re: Brave New Trusted Boot World
#32I'm OK with making sure the software I'm running is the software I thought I was running. But because trusted boot runs so deep, and is intentionally hard to get around, it's vital that the implementation is trustworthy. I don't trust Poetteringware. Poettering's team has a record of foisting technology on users, resulting in the need for e.g. the Devuan fork. I wish this work were being done by just about any other…
> I don't trust Poetteringware. Poettering's team has a record of foisting technology on users, resulting in the need for e.g. the Devuan fork. They have been developing software, that enough people have deemed useful to include it in their distributions. Some have disagreed, and have made other choices. No one was forced to do anything, there have been no "foisting" and the "need" for Devuan is a subjective opinion.…
While I agree with you in general, for some reason this particular developer tends to take decisions that have very extensive consequences and make choice extremely difficult.
Re: Brave New Trusted Boot World
#33As somone who never really viewed systemd as a problem I'm starting to think the systemd "haters" were actually right, at least somewhat... Viewing Poettering as some kind malicious entity undermining projects sounds like a conspiracy theory. But now with him working for Microsoft his actions do look like a lot like the "embrace, extend, and extinguish" pattern to me. Yes, yes "Microsoft And now I am supposed to chee…
Re: Brave New Trusted Boot World
#34Earlier quoted context omitted.
> I don't trust Poetteringware. Poettering's team has a record of foisting technology on users, resulting in the need for e.g. the Devuan fork. They have been developing software, that enough people have deemed useful to include it in their distributions. Some have disagreed, and have made other choices. No one was forced to do anything, there have been no "foisting" and the "need" for Devuan is a subjective opinion.…
> There is really no need to transform purely technical arguments into personal attacks. This just discourages participating into free software development. While I agree with you in general, for some reason this particular developer tends to take decisions that have very extensive consequences and make choice extremely difficult.
He definitely isn't perfect but this sounds like quite the feat in Open Source.
Re: Brave New Trusted Boot World
#35I'm OK with making sure the software I'm running is the software I thought I was running. But because trusted boot runs so deep, and is intentionally hard to get around, it's vital that the implementation is trustworthy. I don't trust Poetteringware. Poettering's team has a record of foisting technology on users, resulting in the need for e.g. the Devuan fork. I wish this work were being done by just about any other…
Re: Brave New Trusted Boot World
#36Earlier quoted context omitted.
What are, if any, "advantages of remote attestation" besides enforcing DRMs and preventing sideloading/jailbreaking? Preventing those who need access to proprietary systems from using any distro except 1-2 certified ones?
So that you can be confident that your software hosted with a random cloud provider has been faithfully launched? This is why Intel is keeping SGX in their Xeon processors despite killing it off in consumer oriented series--servers benefit greatly from the ability to prove to clients that they are well behaved
Re: Brave New Trusted Boot World
#37As somone who never really viewed systemd as a problem I'm starting to think the systemd "haters" were actually right, at least somewhat... Viewing Poettering as some kind malicious entity undermining projects sounds like a conspiracy theory. But now with him working for Microsoft his actions do look like a lot like the "embrace, extend, and extinguish" pattern to me. Yes, yes "Microsoft And now I am supposed to chee…
Re: Brave New Trusted Boot World
#38Earlier quoted context omitted.
> you can't have one without the other, AFAIK, secure boot can be disabled, both in the BIOS and in the Kernel. In some machines that's not be the case due to contracts with Microsoft, but those already can't run Linux in the first place, so you probably won't buy them for the purpose of running Linux. The suggestions in the original post do not change anything about this.
I am mainly worried about remote attestation encroaching on territory which was traditionally under the user's control. And once this tech reaches critical mass, sure you can disable it however that also means turning your machine into a glorified paperweight that can't access anything arbitrary websites and software.
I want to be able to access all services with whatever client I please. Not be required to run approved software and hardware that puts them in control.
Re: Brave New Trusted Boot World
#39As somone who never really viewed systemd as a problem I'm starting to think the systemd "haters" were actually right, at least somewhat... Viewing Poettering as some kind malicious entity undermining projects sounds like a conspiracy theory. But now with him working for Microsoft his actions do look like a lot like the "embrace, extend, and extinguish" pattern to me. Yes, yes "Microsoft And now I am supposed to chee…
I always thought this outcome was obvious. Systemd controls everything that happens before Linux boots. It controls everything that happens after Linux boots. Might as well call it GNU/Systemd at this point. It's the silent revolution no one wanted. The name itself implies a manifest destiny because System D is 100x greater than System V and they intentionally break POSIX compliance too. Now that the guy who owns the…
Re: Brave New Trusted Boot World
#40Earlier quoted context omitted.
> There is really no need to transform purely technical arguments into personal attacks. This just discourages participating into free software development. While I agree with you in general, for some reason this particular developer tends to take decisions that have very extensive consequences and make choice extremely difficult.
A developer that has been able to make tough choices and drive them well enough to get mass adoption? He definitely isn't perfect but this sounds like quite the feat in Open Source.
*PulseAudio was simply broken but it's not the fault of the author distros picked up aplha-quality software