Live data from Hacker News

Brave New Trusted Boot World

0pointer.net

41–50 of 178 posts

Re: Brave New Trusted Boot World

#41
post #16

Earlier quoted context omitted.

I am mainly worried about remote attestation encroaching on territory which was traditionally under the user's control. And once this tech reaches critical mass, sure you can disable it however that also means turning your machine into a glorified paperweight that can't access anything arbitrary websites and software.

You see this on Android, my banking app requires that it is running an OS approved by a big vendor. Their website, especially the mobile version, is getting more and more tedious to use. I want to be able to access all services with whatever client I please. Not be required to run approved software and hardware that puts them in control.

It sounds like you're demanding to use someone's service on your own terms. I'm not sure why it's obvious that the service provider is under any obligation to entertain your desires.

So.... vote with your feet and choose a bank that shares your values more closely?

Re: Brave New Trusted Boot World

#43

Earlier quoted context omitted.

A developer that has been able to make tough choices and drive them well enough to get mass adoption? He definitely isn't perfect but this sounds like quite the feat in Open Source.

There is a huge difference between a developer who creates a superior project that everybody loves to use so it gets mass adoption and one who makes a product that gets pushed by their employer on everyone whether they want it or not. I don't want to get into details as the subject has been beaten to death but as for Systemd* there was the case of integration with graphical login that made choice difficult. Had the a…

> This is exactly NOT the way to do things in open source.

Someone made a decision, others didn't like it so forked. Sounds like open source is working exactly as it should?

Re: Brave New Trusted Boot World

#44
post #24

I'm OK with making sure the software I'm running is the software I thought I was running. But because trusted boot runs so deep, and is intentionally hard to get around, it's vital that the implementation is trustworthy. I don't trust Poetteringware. Poettering's team has a record of foisting technology on users, resulting in the need for e.g. the Devuan fork. I wish this work were being done by just about any other…

> I don't trust Poetteringware. Poettering's team has a record of foisting technology on users, resulting in the need for e.g. the Devuan fork. They have been developing software, that enough people have deemed useful to include it in their distributions. Some have disagreed, and have made other choices. No one was forced to do anything, there have been no "foisting" and the "need" for Devuan is a subjective opinion.…

Systemd was designed in a way that was more tightly coupled than the alternatives and made adopting it an all-or-nothing proposition, and other projects (particularly Gnome) were also tightly coupled to it. It was absolutely foisted on people: a lot of people didn't want it but found they were nevertheless obliged to install it. The whole thing abused the goodwill of the free software community: systemd folks added systemd-dependent patches to other software, taking advantage of the norm of accepting such contributions, while refusing patches that made systemd compatible with other systems (e.g. non-Linux). And the end result was a state where you can no longer fork and replace components piecemeal - the whole free software ethos, the very reason GNU was built as a Unix-like system in the first place - which does far more to discourage participating in free software development than any mere internet argument.

Re: Brave New Trusted Boot World

#45
post #41

Earlier quoted context omitted.

You see this on Android, my banking app requires that it is running an OS approved by a big vendor. Their website, especially the mobile version, is getting more and more tedious to use. I want to be able to access all services with whatever client I please. Not be required to run approved software and hardware that puts them in control.

It sounds like you're demanding to use someone's service on your own terms. I'm not sure why it's obvious that the service provider is under any obligation to entertain your desires. So.... vote with your feet and choose a bank that shares your values more closely?

You have a point that the problem isn't the technology but the policy. However the fact is that most banks are moving in this direction so it leaves a consumer little choice.

Re: Brave New Trusted Boot World

#46
post #43

Earlier quoted context omitted.

There is a huge difference between a developer who creates a superior project that everybody loves to use so it gets mass adoption and one who makes a product that gets pushed by their employer on everyone whether they want it or not. I don't want to get into details as the subject has been beaten to death but as for Systemd* there was the case of integration with graphical login that made choice difficult. Had the a…

> This is exactly NOT the way to do things in open source. Someone made a decision, others didn't like it so forked. Sounds like open source is working exactly as it should?

For applications, tools, even most libraries - yes. But this was one of the critical elements of the system and they had to fork the entire distro because the way it was done actually made the choice more limited.

Re: Brave New Trusted Boot World

#47
post #41

Earlier quoted context omitted.

You see this on Android, my banking app requires that it is running an OS approved by a big vendor. Their website, especially the mobile version, is getting more and more tedious to use. I want to be able to access all services with whatever client I please. Not be required to run approved software and hardware that puts them in control.

It sounds like you're demanding to use someone's service on your own terms. I'm not sure why it's obvious that the service provider is under any obligation to entertain your desires. So.... vote with your feet and choose a bank that shares your values more closely?

>I'm not sure why it's obvious that the service provider is under any obligation to entertain your desires.

They are not obliged by law in any way. However leading up to this point, whatever happens on my side of the network socket has been my discretion. Disrupting this dynamic just bothers me.

Re: Brave New Trusted Boot World

#48
post #4
post #2

>System ready for easy remote attestation, to prove validity of booted OS, configuration and local identity >“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated. In what world is this a…

If I was responsible for a large enough fleet of machines in my enterprise and I would have to deal with 100s of users of various technical knowledge while at the same time being blamed for the eventual ransomware attack, I would absolutely want to make sure that the only software that gets to run is the one I want running. This (especially) includes the machine's firmware and kernel because that's where malware coul…

> If I was responsible for ... the only software that gets to run is the one I want running.

Not wishing to pick on you personally, but the above paragraph is wonderful example of the sort of logic going around that bothers me.

You trace a faultless journey from responsibility to desiring total control.

That's not what responsibility is.

You're describing the feeling of culpability within a brutal regime - where Vader simply force-chokes a lieutenant for "failing me once too often".

Responsibility involves leadership, which involves not stripping every subordinate of their agency, dignity and humanity. It involves trusting people. Sadly, computers make a "zero trust" ecosystem far too easy now, and that's how they can destroy our society. Good computing is figuring out ways to preserve liberal democratic society while also improving it.

Re: Brave New Trusted Boot World

#49
post #41

Earlier quoted context omitted.

You see this on Android, my banking app requires that it is running an OS approved by a big vendor. Their website, especially the mobile version, is getting more and more tedious to use. I want to be able to access all services with whatever client I please. Not be required to run approved software and hardware that puts them in control.

It sounds like you're demanding to use someone's service on your own terms. I'm not sure why it's obvious that the service provider is under any obligation to entertain your desires. So.... vote with your feet and choose a bank that shares your values more closely?

> So.... vote with your feet and choose a bank that shares your values more closely?

That never worked and will not work now. You can't choose something that's not being offered.

EDIT:

Also,

> It sounds like you're demanding to use someone's service on your own terms.

Well, sort of; a service agreement is a relationship, and TPM/remote attestation is a huge overreach by the corporate party. It's only fair to want to push back on what's becoming an abusive relationship.

Re: Brave New Trusted Boot World

#50
post #2

>System ready for easy remote attestation, to prove validity of booted OS, configuration and local identity >“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated. In what world is this a…

Many folks prioritize preventing practical in-the-wild blue pill attacks over preventing the theoretical DRM use case.

It's not a "theoretical DRM use case" if you stop thinking in terms of movie piracy for a moment, and consider what's happening with banking apps on mobile platforms.

Thanks to remote attestation, the custom ROM scene for Android is pretty much dead now, because there's little point of customizing the OS when it automatically makes important services no longer accessible from the phone.

Post reply on HN