Live data from Hacker News

Lennart Poettering, Christian Brauner founded a new company

amutable.com

281–290 of 770 posts

Re: Lennart Poettering, Christian Brauner founded a new company

#284
post #170

Earlier quoted context omitted.

yeah, the fix for pulseaudio was to throw it away entirely for systemd, I don't think I have a single linux system that boots/reboots reliably 100% of the time these days

The trick is the same: use a popular linux distribution and don't fight the kinks. The people who had no issues with Pulseaudio; used a mainstream distribution. Those distributions did the heavy lifting of making sure stuff fit together in a cohesive way. SystemD is very opinionated, so you'd assume it wouldn't have the same results, but it does.. if you use a popular distro then they've done a lot of the hard work t…

"The trick is the same: use a popular linux distribution and don't fight the kinks."

I believe that you are genuinely being sincere here, thinking this is good advice.

But this is an absolutely terrible philosophy. This statement is ignorant as well as inconsiderate. (again, I do believbe you don't intend to be inconsiderate consciously, that is just the result.)

It's ignorant of history and inconsiderate of everyone else but yourself.

Go back a few years and this same logic says "The trick is, just use Windows and do whatever it wants and don't fight."

So why in the world are you even using Linux at all in the first place with that attitude? For dishonest reasons (when unpacked to show the double standard).

Since you are using Linux instead of Windows, then you actually are fine with fighting the tide. You want the particular bits of control you want, and as long as you are lucky enough to get whatever you happen to care about without fighting too much, then you have no sympathy for anyone else who cares aboiut anything else.

You don't see yourself as fighting any tides because you are benefitting from being able to use a mainstream distro without customizing it. But the only reason you get to enjoy any such thing at all in the first place is because a lot of other people before you fought the tide to bring some mainstream distros into existence, and actually use them for ordinary activities enough despite all the difficulties, to force at least some companies and government agencies to acknowledge them. So now you can say things like "just use a mainstream distro as it comes and don't try to do what you actually want".

Re: Lennart Poettering, Christian Brauner founded a new company

#285
post #271

Earlier quoted context omitted.

Afaik bankid will actually run as long as you can install play store (IE the device don't need Google certificate), which isn't great but a little bit better than what it could have been.

That can't be right. My onyx boox note air 2 eInk tablet lets me install the google play store by registering myself as an AOSP developer and enrolling my device's serial number or GSF identifier with Google using some Google Form that some android team somewhere's automated by now. The device has no hardware security features from what I can tell. There's no way this platform would pass muster with any bank.

I have the successor device, the Boox Note Air 2, and don't remember how I installed Google Play on it, it was so easy as to be not even notable. Though almost everything I use is available on F-Droid other than my fancy calendar and contacts applications.

Re: Lennart Poettering, Christian Brauner founded a new company

#286

Earlier quoted context omitted.

that's a silver lining the anti-user attestation will at least be full of security holes, and likely won't work at all

Dunno about the others but Pottering has proven himself to deliver software against the grain.

LP is the Thomas Midgley Jr of Computer Science.

Re: Lennart Poettering, Christian Brauner founded a new company

#287

Earlier quoted context omitted.

everyone attacking Microslop for a bug where Windows won't shut down properly well, systemd's got them beat there!

The good thing about systemd or any other Linux software is that you don't have to use it, until this company gets off the ground.

I think at some point we will see a steep increase in value of old hardware that can still run unsigned binaries.

Re: Lennart Poettering, Christian Brauner founded a new company

#288
post #280

Earlier quoted context omitted.

Have you run an Android device recently?

Yes, I reference Android client attestation in my comments in this thread frequently. I actually see this company as likely to be the flip side of the “bad” client attestation coin; server attestation actually provides a lot of nice properties to end users and providers who wish to provide secure solutions with very limited user downside.

It won't remain "server" attestation. It will become "client" attestation, with the end result that you won't own your own machine anymore, you'll just be paying for a client device upon which you won't control the hardware or software anymore. See any mobile phone at all, anymore.

Re: Lennart Poettering, Christian Brauner founded a new company

#290

Earlier quoted context omitted.

> Trusted boot is literally a form of DRM. A different one than remote attestation. No, it's not. (And for that matter, neither is remote attestation) You're conflating the technology with the use. I believe that you have only thought about these technologies as they pertain to DRM, now I'm here to tell you there are other valid use cases. Or maybe your definition of "DRM" is so broad that it includes me setting up m…

It's possible to not implement remote attestation even when you implement secure boot. This company is explicitly all about implementing remote attestation (which is a form of DRM): https://amutable.com/events > Remote Attestation of Imutable Operating Systems built on systemd > Lennart Poettering

> This company is explicitly all about implementing remote attestation (which is a form of DRM):

Is there a HN full moon out?

Again, this is wrong.

DRM is a policy.

Remote attestation is a technology.

You can use remote attestation to implement DRM.

You can also use remote attestation to implement other things.

Post reply on HN