Live data from Hacker News

Brave New Trusted Boot World

0pointer.net

61–70 of 178 posts

Re: Brave New Trusted Boot World

#61
post #39
post #33

Earlier quoted context omitted.

I always thought this outcome was obvious. Systemd controls everything that happens before Linux boots. It controls everything that happens after Linux boots. Might as well call it GNU/Systemd at this point. It's the silent revolution no one wanted. The name itself implies a manifest destiny because System D is 100x greater than System V and they intentionally break POSIX compliance too. Now that the guy who owns the…

No-one's making you use it. Choose a distro that doesn't package it - there's plenty to choose from.

[deleted]

Re: Brave New Trusted Boot World

#62
post #44
post #24

Earlier quoted context omitted.

> I don't trust Poetteringware. Poettering's team has a record of foisting technology on users, resulting in the need for e.g. the Devuan fork. They have been developing software, that enough people have deemed useful to include it in their distributions. Some have disagreed, and have made other choices. No one was forced to do anything, there have been no "foisting" and the "need" for Devuan is a subjective opinion.…

Systemd was designed in a way that was more tightly coupled than the alternatives and made adopting it an all-or-nothing proposition, and other projects (particularly Gnome) were also tightly coupled to it. It was absolutely foisted on people: a lot of people didn't want it but found they were nevertheless obliged to install it. The whole thing abused the goodwill of the free software community: systemd folks added s…

The tight coupling, the non-portability, all of that are technical choices, that can be debated on their own merit without the need to attribute malevolent intentions to the developers.

Projects merged changes because they wanted them, not because their goodwill was abused to make them merge anything. People got systemd on their OSes because they chose OSes whose developers chose to move to systemd.

It's not like Lennart comes to your home with a gun if you install OpenBSD.

Re: Brave New Trusted Boot World

#63
post #10
post #4

Earlier quoted context omitted.

If I was responsible for a large enough fleet of machines in my enterprise and I would have to deal with 100s of users of various technical knowledge while at the same time being blamed for the eventual ransomware attack, I would absolutely want to make sure that the only software that gets to run is the one I want running. This (especially) includes the machine's firmware and kernel because that's where malware coul…

>This isn't about your own private machine. This is about corporation-owned machines in an enterprise network and as we see with nearly biweekly news articles about large-scale ransomware attacks, private data leaks and compromised employee machines, I would argue that the currently employed solutions clearly don't work. The fundamental issue is that you can't have one without the other, and that's bothering me. It's…

[deleted]

Re: Brave New Trusted Boot World

#64

Earlier quoted context omitted.

It's not a "theoretical DRM use case" if you stop thinking in terms of movie piracy for a moment, and consider what's happening with banking apps on mobile platforms. Thanks to remote attestation, the custom ROM scene for Android is pretty much dead now, because there's little point of customizing the OS when it automatically makes important services no longer accessible from the phone.

That's the entire point. Your bank doesn't want you to run their software on your potentially vulnerable hardware.

That's the entire point of conflict: to me, that's an overreach by the bank, who's now dictating things out of scope of the relationship between us.

The traditional boundary is one drawn by device ownership: my device, my rules; their device, their rules. I.e. my phone can do whatever, their servers can refuse working with me.

Remote attestation is at best a way for simplifying their own service, at a big cost to users' freedom. In reality, it's a bit of that, plus mostly making sure the customers are locked into a bank-controlled channel that can be used to upsell more financial products.

Re: Brave New Trusted Boot World

#65
post #4

Earlier quoted context omitted.

If I was responsible for a large enough fleet of machines in my enterprise and I would have to deal with 100s of users of various technical knowledge while at the same time being blamed for the eventual ransomware attack, I would absolutely want to make sure that the only software that gets to run is the one I want running. This (especially) includes the machine's firmware and kernel because that's where malware coul…

> If I was responsible for ... the only software that gets to run is the one I want running. Not wishing to pick on you personally, but the above paragraph is wonderful example of the sort of logic going around that bothers me. You trace a faultless journey from responsibility to desiring total control. That's not what responsibility is. You're describing the feeling of culpability within a brutal regime - where Vade…

The problem isn’t that you can’t trust people. The problem is that people are defenseless in the face of malicious hackers with vastly more expertise and zero day vulnerabilities.

It’s not that you can’t trust your employees. It’s that you can’t trust them to defend themselves from being mugged.

The forcing function for all this removal of freedom is defense against malicious hackers. The removal of freedom is not the goal so much as a side effect.

It works the same way in the real world. We would not need borders or armies or police if everyone were nice.

Re: Brave New Trusted Boot World

#66
I've never understood the need for all the complexity.

Security should be built from the ground up from two physical ports. One is a file storage like SD card and one is a hasher/checker for the blobs that are read form that storage device. One of the blobs should be the CPU microcode. The system can be expanded with additional (tag,blobs).

There. Solved every solvable use case.

Okay, i lied. I do understand why there is a need for all the complexity. Some sysadmins and DRM believers think the complex solution makes their lives easier by being remotely controlled and being "good enough".

Because nobody could ever care enough to tinker with 'baked in' secrets and if they do its above your pay-grade.

Re: Brave New Trusted Boot World

#67
post #56
post #39

Earlier quoted context omitted.

No-one's making you use it. Choose a distro that doesn't package it - there's plenty to choose from.

This number diminishes every passing year, with only debian being a bastion of sanity on the "user friendly" side of the distro spectrum.

Why do you think that is?

Re: Brave New Trusted Boot World

#68
post #39
post #33

Earlier quoted context omitted.

I always thought this outcome was obvious. Systemd controls everything that happens before Linux boots. It controls everything that happens after Linux boots. Might as well call it GNU/Systemd at this point. It's the silent revolution no one wanted. The name itself implies a manifest destiny because System D is 100x greater than System V and they intentionally break POSIX compliance too. Now that the guy who owns the…

No-one's making you use it. Choose a distro that doesn't package it - there's plenty to choose from.

This is unfair. MS keeps making it harder and harder to run anything that is not MS-signed (TM) on Secure Boot hardware; any distro that does not bow to the whims of MS is thus likely to be relegated to obscurity or die due to lack of users capable of installing it.

Re: Brave New Trusted Boot World

#69
post #59

Earlier quoted context omitted.

To preempt the "but slippery slope!" counters, where we're currently at is "you may not use your bank's mobile app on a phone that isn't running genuine, unmodded, unrooted version of the hardware and OS it came with". This is the reality of modern Android devices. And it's not worse only because, like with any API, adoption of new-and-improved Safenet / Play $forgot-the-name APIs takes time. The slippery slope is no…

At least so far my bank hasn't prevented me from using my web browser on linux to access the banking website. But I am certain they will once Windows 11 gets enough traction in a few years.

Yes, websites are still the one place where users have some degree of parity with the vendors. They are, however, being actively phased out. It's a long process, but it's clear. New banks and quasi-banks often don't even have a web portal. Old-school banks have been actively pushing apps as the primary interface. In recent years, they've been pushing apps as preferred auth mechanism for confirming logins and transactions initiated off-app. How long before it'll become the only mechanism?

Re: Brave New Trusted Boot World

#70

Earlier quoted context omitted.

It's not a "theoretical DRM use case" if you stop thinking in terms of movie piracy for a moment, and consider what's happening with banking apps on mobile platforms. Thanks to remote attestation, the custom ROM scene for Android is pretty much dead now, because there's little point of customizing the OS when it automatically makes important services no longer accessible from the phone.

That's the entire point. Your bank doesn't want you to run their software on your potentially vulnerable hardware.

Right — the bank is trying to control how I use their service “for my own safety”.

That’s not a theoretic DRM issue, but a practical attack on the software ecosystem.

Post reply on HN