What is the endgame here? Obviously "heightened security" in some kind of sense, but to what end and what mechanisms? What is the scope of the work? Is this work meant to secure forges and upstream development processes via more rigid identity verification, or package manager and userspace-level runtime restrictions like code signing? Will there be a push to integrate this work into distributions, organizations, or t…
Lennart Poettering, Christian Brauner founded a new company
211–220 of 770 posts
Re: Lennart Poettering, Christian Brauner founded a new company
#212Earlier quoted context omitted.
Remote attestation is literally a form of DRM
> Remote attestation is literally a form of DRM Let's say I accept this statement. What makes you think trusted boot == remote attestation?
Re: Lennart Poettering, Christian Brauner founded a new company
#213[flagged]
Re: Lennart Poettering, Christian Brauner founded a new company
#214Earlier quoted context omitted.
I only use debian pulseaudio I had to fight every single day, with my "exotic" setup of one set of speakers and a headset with pipewire, I've never had to even touch it systemd: yesterday I had a network service on one machine not start up because the IP it was trying to bind to wasn't available yet the dependencies for the .service file didn't/can't express the networking semantics correctly this isn't some hacked u…
> it's literally a new random problem every other boot because of this non-deterministic startup, which was never a problem with traditional init or /etc/rc This gave me a good chuckle. Systemd literally was created to solve the awful race conditions and non-determinism in other init systems. And it has done a tremendous job at it. Hence the litany of options to ensure correct order and execution: https://www.freedes…
like "at least one real IP address is available" or "time has been synced"
and it's not esoteric, even ListenAddress with sshd doesn't even work reliably
the ONLY piece of systemd I've not had problems with is systemd-boot, and then it turned out they didn't write that
Re: Lennart Poettering, Christian Brauner founded a new company
#215So I imagine Lennart Poettering has left Microsoft.
Re: Lennart Poettering, Christian Brauner founded a new company
#216Earlier quoted context omitted.
Only by creating a new stalemate between essential liberty and a little temporary security — anticheat doesn't protect you from DMA cheating.
I might be behind on the latest counter-counter-counter-measures, but I know some of the leading AC solutions are already using IOMMU to wedge a firewall between passive DMA sniffers and the game processes memory. e.g. https://support.faceit.com/hc/en-us/articles/19590307650588-...
Re: Lennart Poettering, Christian Brauner founded a new company
#217This seems like the kind of technology that could make the problem described in https://www.gnu.org/philosophy/can-you-trust.en.html a lot worse. Do you have any plans for making sure it doesn't get used for that?
I'm Aleksa, one of the founding engineers. We will share more about this in the coming months but this is not the direction nor intention of what we are working on. The models we have in mind for attestation are very much based on users having full control of their keys. This is not just a matter of user freedom, in practice being able to do this is far more preferable for enterprises with strict security controls. I…
Until you get acquired, receive a golden parachute and use it when realizing that the new direction does not align with your views anymore.
But, granted, if all you do is FOSS then you will anyway have a hard time keeping evil actors from using your tech for evil things. Might as well get some money out of it, if they actually dump money on you.
Re: Lennart Poettering, Christian Brauner founded a new company
#218Earlier quoted context omitted.
that's a silver lining the anti-user attestation will at least be full of security holes, and likely won't work at all
Dunno about the others but Pottering has proven himself to deliver software against the grain.
Re: Lennart Poettering, Christian Brauner founded a new company
#219Really excited to a company investing into immutable and cryptographically verifiable systems. Two questions really: 1. How will the company make money? (You have probably been asked that a million times :).) 2. Similar to the sibling: what are the first bits that you are going to work on. At any rate, super cool and very nice that you are based in EU/Germany/Berlin!
Re: Lennart Poettering, Christian Brauner founded a new company
#220Hi Chris, One of the most grating pain points of the early versions of systemd was a general lack of humility, some would say rank arrogance, displayed by the project lead and his orbiters. Today systemd is in a state of "not great, not terrible" but it was (and in some circles still is) notorious for breaking peoples' linux installs, their workflows, and generally just causing a lot of headaches. The systemd project…