Lennart Poettering, Christian Brauner founded a new company
101–110 of 770 posts
Re: Lennart Poettering, Christian Brauner founded a new company
#102Earlier quoted context omitted.
> but considering Windows requirements drive the PC spec, this capability can be used to force Linux distributions in bad ways What do you mean by this? Is the concern that systemd is suddenly going to require that users enable some kind of attestation functionality? That making attestation possible or easier is going to cause third parties to start requiring it for client machines running Linux? This doesn't even re…
Microsoft has a "minimum set of requirements" document about "Designed for Windows" PCs. You can't sell a machine with Windows or tell it's Windows compatible without complying with that checklist. So, every PC sold to consumers is sanctioned by Microsoft. This list contains Secure Boot and TPM based requirements, too. If Microsoft decides to eliminate enrollment of user keys and Secure Boot toggle, they can revoke c…
Re: Lennart Poettering, Christian Brauner founded a new company
#103Exciting! It sounds like you want to achieve system transparency, but I don't see any clear mention of reproducible builds or transparency logs anywhere. I have followed systemd's efforts into Secure Boot and TPM use with great interest. It has become increasingly clear that you are heading in a very similar direction to these projects: - Hal Finney's transparent server - Keylime - System Transparency - Project Oak -…
Hi, I'm David, founding product lead. Our entire team will be at FOSDEM, and we'd be thrilled to meet more of the Mullvad team. Protecting systems like yours is core to us. We want to understand how we put the right roots of trust and observability into your hands. Edit: I've reached out privately by email for next steps, as you requested.
As I mentioned above, we've followed systemd's development in recent years with great interest, as well as that of some other projects. When I started(*) the System Transparency project it was very much a research project.
Today, almost seven years later, I think there's a great opportunity for us to reduce our maintenance burden by re-architecting on top of systemd, and some other things. That way we can focus on other things. There's still a lot of work to do on standardizing transparency building blocks, the witness ecosystem(**), and building an authentication mechanism for system transparency that weaves it all together.
I'm more than happy to share my notes with you. Best case you build exactly what we want. Then we don't have to do it. :)
Re: Lennart Poettering, Christian Brauner founded a new company
#104Earlier quoted context omitted.
> Sounds like kernel mode DRM or some similarly unwanted bullshit. Look, I hate systemd just as much as the next guy - but how are you getting "DRM" out of this?
Hacker News has recently been dominated by conspiracy theorists who believe that all applications of cryptography are evil attempts by shadowy corporate overlords to dominate their use of computing.
Re: Lennart Poettering, Christian Brauner founded a new company
#105Re: Lennart Poettering, Christian Brauner founded a new company
#106Re: Lennart Poettering, Christian Brauner founded a new company
#107Earlier quoted context omitted.
The problem is not systemd vs SysV et al, the problem is systemd spreading like a cancer throughout the entire operating system. Also trying to use systemd with podman is frustrating as hell. You just cannot run a system service using podman as a non-root user and have it work correctly.
Quadlet actually solves this. It's the newer way to define containers for systemd and handles the rootless user case properly. I migrated my services to it recently and it's much more robust than the old generate scripts.
Re: Lennart Poettering, Christian Brauner founded a new company
#108Earlier quoted context omitted.
1. We are confident we have a very robust path to revenue. 2. Given the team, it should be quite obvious there will be a Linux-based OS involved. Our aims are global but we certainly look forward to playing an important role in the European tech landscape.
"We are confident we have a very robust path to revenue." I take it that you are not at this stage able to provide details of the nature of the path to revenue. On what kind of timescale do you envisage being able to disclose your revenue stream/subscribers/investors?
As I understand it, the main customers for this sort of thing are companies making Tivo-style products - where they want to use Linux in their product, but they want to lock it down so it can't be modified by the device owner.
This can be pretty profitable; once your customers have rolled out a fleet of hardware locked down to only run kernels you've signed.
Re: Lennart Poettering, Christian Brauner founded a new company
#109Earlier quoted context omitted.
Microsoft has a "minimum set of requirements" document about "Designed for Windows" PCs. You can't sell a machine with Windows or tell it's Windows compatible without complying with that checklist. So, every PC sold to consumers is sanctioned by Microsoft. This list contains Secure Boot and TPM based requirements, too. If Microsoft decides to eliminate enrollment of user keys and Secure Boot toggle, they can revoke c…
I don't see how this relates in any way to Amutable and it has been a "concern" for 20+ years (which has never come to pass). How do you think this relates at all?
Now we have immutable distributions (SuSE, Fedora, NixOS). We have the infrastructure for attestation (systemd's UKI, image based boot, and other immutability features), TPMs and controversially uutils (Which is MIT licensed and has the stated goal to replace all GNU userspace).
You can build an immutable and adversarial userspace where you don't have to share the source, and require every boot and application call to attest. The theoretical thickness of the wall is both much greater and this theoretical state is much easier to achieve.
20 years ago the only barrier was booting. After that everything was free. Now it's possible to boot into a prison where your every ls and cd command can be attested.
Oh, Rust is memory safe. Good luck finding holes.
Re: Lennart Poettering, Christian Brauner founded a new company
#110What does this mean? Why would anyone want this? Can you explain this to me like I'm five years old?