Earlier quoted context omitted.
It's probably built on systemd's Secure Boot + immutability support. As said above, it's about who controls the keys. It's either building your own castle or having to live with the Ultimate TiVo. We'll see.
We all know who controls the keys. It's the first party who puts their hands on the device.
Lennart Poettering, Christian Brauner founded a new company
161–170 of 770 posts
Re: Lennart Poettering, Christian Brauner founded a new company
#162Re: Lennart Poettering, Christian Brauner founded a new company
#163Earlier quoted context omitted.
Dunno about the others but Pottering has proven himself to deliver software against the grain.
You think? It took us nearly a decade and a half to unfuck the pulseaudio situation and finally arrive at a simple solution (pipewire). SystemD has a lot more people refining it down but a clean (under the hood) implementation probably won't be witnessed in my lifetime.
for systemd, I don't think I have a single linux system that boots/reboots reliably 100% of the time these days
Re: Lennart Poettering, Christian Brauner founded a new company
#164Earlier quoted context omitted.
> Secure Boot allows you to enroll your own keys UEFI secure boot on PCs, yes for the most part. A lot of mobile platforms just never supported this. It's not a myth.
Phones don't implement UEFI.
Re: Lennart Poettering, Christian Brauner founded a new company
#165Earlier quoted context omitted.
You won't believe how many hours we have lost troubleshooting SysV init and Upstart issues. systemd is so much better in every way, reliable parallel init with dependencies, proper handling of double forking, much easier to secure services ( systemd-analyze security ), proper timer handling (yay, no more cron), proper temporary file/directory handling, centralized logs, etc. It improves on about every level compared…
"In every way" About ten years ago I took a three day cross-country Amtrak trip where I wanted to work on some data analysis that used mysql for its backend. It was a great venue for that sort of work because the lack of train-internet was wonderful to keep me focused. The data I was working with was about 20GB of parking ticket data. The data took a while to process over SQL which gave me the chance to check out the…
https://bugzilla.redhat.com/show_bug.cgi?id=1780979
https://github.com/systemd/systemd/commit/a083b4875e8dec5ce5...
That was far from the only time that the systemd developers decided to just break norms or do weird things because they felt like it, and then poorly communicate that change. Change itself is fine, it's how we progress. But part of that arrogance that you mentioned was always framing people who didn't like capricious or poorly communicated changes as being against progress, and that's always been the most annoying part of the whole thing.
Re: Lennart Poettering, Christian Brauner founded a new company
#166Earlier quoted context omitted.
Just an assumption here, but the project appears to be about the methodology to verify the install. Who holds the keys is an entirely different matter.
Werner Von Braun only built the rockets; he didn't aim them, nor did he care where they landed. (London. On some of my relatives.)
Re: Lennart Poettering, Christian Brauner founded a new company
#167Re: Lennart Poettering, Christian Brauner founded a new company
#168The typical HN rage-posting about DRM aside, there's no reason that remote attestation can't be used in the opposite direction: to assert that a server is running only the exact code stack it claims to be, avoiding backdoors. This can even be used with fully open-source software, creating an opportunity for OSS cloud-hosted services which can guarantee that the OSS and the build running on the server match. This is a…
Like evil maid attacks, this is a vanishingly rare scenario brought out to try to justify technology that will overwhelmingly be used to restrict computing freedom.
Re: Lennart Poettering, Christian Brauner founded a new company
#169Remote attestation is another technology that is not inherently restrictive of software freedom. But here are some examples of technologies that have already restricted freedom due to oligopoly combined with network effects: * smartphone device integrity checks (SafetyNet / Play Integrity / Apple DeviceCheck) * HDMI/HDCP * streaming DRM (Widevine / FairPlay) * Secure Boot (vendor-keyed deployments) * printers w/ sign…
Re: Lennart Poettering, Christian Brauner founded a new company
#170Earlier quoted context omitted.
You think? It took us nearly a decade and a half to unfuck the pulseaudio situation and finally arrive at a simple solution (pipewire). SystemD has a lot more people refining it down but a clean (under the hood) implementation probably won't be witnessed in my lifetime.
yeah, the fix for pulseaudio was to throw it away entirely for systemd, I don't think I have a single linux system that boots/reboots reliably 100% of the time these days
The people who had no issues with Pulseaudio; used a mainstream distribution. Those distributions did the heavy lifting of making sure stuff fit together in a cohesive way.
SystemD is very opinionated, so you'd assume it wouldn't have the same results, but it does.. if you use a popular distro then they've done a lot of the hard work that makes systemd function smooth.
I was today years old when I realised this is true for both bits of poetter-ware. Weird.