Earlier quoted context omitted.
Unfortunately the parent commenter is completely right. The attestation portion of those systems is happening on locked down devices, and if you gain ownership of the devices they no longer attest themselves. This is the curse of the duopoly of iOS and Android. BankID in Sweden will only run with one of these devices, they used to offer a card system but getting one seems to be impossible these days. So you're really…
Afaik bankid will actually run as long as you can install play store (IE the device don't need Google certificate), which isn't great but a little bit better than what it could have been.
Lennart Poettering, Christian Brauner founded a new company
271–280 of 770 posts
Re: Lennart Poettering, Christian Brauner founded a new company
#272Earlier quoted context omitted.
Trusted boot is literally a form of DRM. A different one than remote attestation.
> Trusted boot is literally a form of DRM. A different one than remote attestation. No, it's not. (And for that matter, neither is remote attestation) You're conflating the technology with the use. I believe that you have only thought about these technologies as they pertain to DRM, now I'm here to tell you there are other valid use cases. Or maybe your definition of "DRM" is so broad that it includes me setting up m…
This company is explicitly all about implementing remote attestation (which is a form of DRM):
> Remote Attestation of Imutable Operating Systems built on systemd
> Lennart Poettering
Re: Lennart Poettering, Christian Brauner founded a new company
#273To me this looks bad on so many levels. I hate it immediately. One good news is that maybe LP will get less involved in systemd.
Re: Lennart Poettering, Christian Brauner founded a new company
#274Re: Lennart Poettering, Christian Brauner founded a new company
#275Earlier quoted context omitted.
You're absolutely right , but considering Windows requirements drive the PC spec, this capability can be used to force Linux distributions in bad ways. So, some of the people doing "typical HN rage-posting about DRM" are also absolutely right . The capabilities locking down macOS and iOS and related hardware also can be used for good, but they are not used for that.
> but considering Windows requirements drive the PC spec, this capability can be used to force Linux distributions in bad ways What do you mean by this? Is the concern that systemd is suddenly going to require that users enable some kind of attestation functionality? That making attestation possible or easier is going to cause third parties to start requiring it for client machines running Linux? This doesn't even re…
Re: Lennart Poettering, Christian Brauner founded a new company
#276Earlier quoted context omitted.
> Interesting. So what did the attestation say once I (random Internet user) updated the firmware to something I wrote or compiled from another source? The update is predicated on a valid signature.
So your device had no user freedom. You're not doing much to refute the notion that these technologies are only useful to severely restrict user freedom for money.
Would love to hear more of your thoughts on how the users of the device I worked on had their freedom restricted!
I guess my company, the user of the device that I worked on, was being harmed by my company, the creator of the device that I worked on. It's too bad that my company chose to restrict the user's freedom in this way.
Who cares if the application of the device was an industrial control scenario where errors are practically guaranteed to result in the loss of human life, and as a result are incredibly high value targets ala Stuxnet.
No, the users rights to run any code trumps everything! Commercial device or not, ever sold outside of the company or not, terrorist firmware update or not - this right shall not be infringed.
I now recognize I have committed a great sin, and hope you will forgive me.
Re: Lennart Poettering, Christian Brauner founded a new company
#277Earlier quoted context omitted.
It very clearly is restrictive of software freedom. I've never suffered from an evil maid breaking into my house to access my computer, but I've _very_ frequently suffered from corporations trying to prevent me from doing what I wish with my own things. We need to push back on this notion that this sort of thing was _ever_ for the end-user's benefit, because it's not.
To play devil's advocate, I don't think most people would be fine with their car ramming into a military base after an unfriendly firmware update. However, I agree that the risks to individuals and their freedoms stemming from these technologies outweigh the benefits in most cases.
Re: Lennart Poettering, Christian Brauner founded a new company
#278To me this looks bad on so many levels. I hate it immediately. One good news is that maybe LP will get less involved in systemd.
If you're going to flame it you might as well point out something concrete you don't like about it.
See Android; or, where you no longer own your device, and if the company decides, you no longer own your data or access to it.
Re: Lennart Poettering, Christian Brauner founded a new company
#279Earlier quoted context omitted.
The trick is the same: use a popular linux distribution and don't fight the kinks. The people who had no issues with Pulseaudio; used a mainstream distribution. Those distributions did the heavy lifting of making sure stuff fit together in a cohesive way. SystemD is very opinionated, so you'd assume it wouldn't have the same results, but it does.. if you use a popular distro then they've done a lot of the hard work t…
I only use debian pulseaudio I had to fight every single day, with my "exotic" setup of one set of speakers and a headset with pipewire, I've never had to even touch it systemd: yesterday I had a network service on one machine not start up because the IP it was trying to bind to wasn't available yet the dependencies for the .service file didn't/can't express the networking semantics correctly this isn't some hacked u…
IIRC before PulseAudio we had to mess around with ALSA directly (memory hazy, it was a while ago). It could be a bit of a pain.
Re: Lennart Poettering, Christian Brauner founded a new company
#280Earlier quoted context omitted.
> but considering Windows requirements drive the PC spec, this capability can be used to force Linux distributions in bad ways What do you mean by this? Is the concern that systemd is suddenly going to require that users enable some kind of attestation functionality? That making attestation possible or easier is going to cause third parties to start requiring it for client machines running Linux? This doesn't even re…
Have you run an Android device recently?