Live data from Hacker News

Lennart Poettering, Christian Brauner founded a new company

amutable.com

301–310 of 770 posts

Re: Lennart Poettering, Christian Brauner founded a new company

#301
post #294

Earlier quoted context omitted.

This is basically propaganda for the war on general purpose computing. My user data is less safe on a Windows device, because Microsoft has full access to that device and they are extremely untrustworthy. On my Linux device, I choose the software to install.

What are you talking about? This has nothing to do with general purpose computing and everything to do with allowing you to authenticate the parts of the Linux boot process that must by necessity be left unencrypted in order to actually boot your computer. This is putting SecureBoot and the TPM to work for your benefit. It's not propaganda in any sense, it's recognizing that Linux is behind the state of the art compa…

Secure boot is initialized by the first person who physically touches the computer and wants to initialize it. Guess who that is? Hint: it's not the final owner.

It's only secure from evil maker attacks if it can be wiped and reinitialised at any time.

Re: Lennart Poettering, Christian Brauner founded a new company

#302
post #185
post #35

Earlier quoted context omitted.

Verifiable to who? Some remote third party that isn't me? The hell would I want that?

https://0pointer.net/blog/authenticated-boot-and-disk-encryp... You. The money quote about the current state of Linux security: > In fact, right now, your data is probably more secure if stored on current ChromeOS, Android, Windows or MacOS devices, than it is on typical Linux distributions. Say what you want about systemd the project but they're the only ones moving foundational Linux security forward, no one else e…

Considering that (for example) your data on ChromeOS is automatically copied to a server run by Google, who are legally compelled to provide a copy to the government when subject to a FISA order, it is unclear what Poettering's threat model is here. Handwringing about secure boot is ludicrous when somebody already has a remote backdoor, which all of the cited operating systems do. Frankly, the assertion of such a naked counterfactual says a lot more about Poettering than it does about Linux security.

Re: Lennart Poettering, Christian Brauner founded a new company

#303

Earlier quoted context omitted.

The good thing about systemd or any other Linux software is that you don't have to use it, until this company gets off the ground.

I think at some point we will see a steep increase in value of old hardware that can still run unsigned binaries.

It won't be able to interact with any online services like Google or Hacker News.

Re: Lennart Poettering, Christian Brauner founded a new company

#304
Everyday the world is becoming more polarized. Technology corporations gain ever more control over people's lives, telling people what they can do on their computers and phones, what they can talk about on social platforms, censoring what they please, wielding the threat of being cutoff from their data, their social circles on a whim. All over the world, in dictatorships and also in democratic countries, governments turn more fascist and more violent. They demonstrate that they can use technology to oppress their population, to hunt dissent and to efficiently spread propaganda.

In that world, authoring technology that enables this even more is either completely mad or evil. To me Linux is not a technological object, it is also a political statement. It is about choice, personal freedom, acceptance of risk. If you build software that actively intends to take this away from me to put it into the hands of economic interests and political actors then you deserve all the hate you can get.

Re: Lennart Poettering, Christian Brauner founded a new company

#305
post #51

This seems like the kind of technology that could make the problem described in https://www.gnu.org/philosophy/can-you-trust.en.html a lot worse. Do you have any plans for making sure it doesn't get used for that?

I'm Aleksa, one of the founding engineers. We will share more about this in the coming months but this is not the direction nor intention of what we are working on. The models we have in mind for attestation are very much based on users having full control of their keys. This is not just a matter of user freedom, in practice being able to do this is far more preferable for enterprises with strict security controls. I…

Can I build my own kernel and still use software that wants attestation?

Re: Lennart Poettering, Christian Brauner founded a new company

#306
post #297

Earlier quoted context omitted.

"The trick is the same: use a popular linux distribution and don't fight the kinks." I believe that you are genuinely being sincere here, thinking this is good advice. But this is an absolutely terrible philosophy. This statement is ignorant as well as inconsiderate. (again, I do believbe you don't intend to be inconsiderate consciously, that is just the result.) It's ignorant of history and inconsiderate of everyone…

I read it as sarcastic and bitter, personally! I believe you are both agreeing :)

hah it fits regardless

Re: Lennart Poettering, Christian Brauner founded a new company

#308

Earlier quoted context omitted.

Daan here, founding engineer and systemd maintainer. So we try to make every new feature that might be disruptive optional in systemd and opt-in. Of course we don't always succeed and there will always be differences in opinion. Also, we're a team of people that started in open source and have done open source for most of our careers. We definitely don't intend to change that at all. Keeping systemd a healthy project…

Hi Daan, Thanks for the answer. Let me ask you something close with a more blunt angle: Considering most of the tech is already present and shipping in the current systemd, what prevents our systems to become a immutable monolith like macOS or current Android with the flick of a switch? Or a more grave scenario: What prevents Microsoft from mandating removal of enrollment permissions for user keychains and Secure Boo…

> What prevents Microsoft from mandating removal of enrollment permissions for user keychains and Secure Boot toggle

Theoretically, nothing. But it's worth pointing out that so far they have actually done the opposite. They currently mandate that hardware vendors must allow you to enroll your own keys. There was a somewhat questionable move recently where they introduced a 'more secure by default' branding in which the 3rd party CA (used e.g. go sign shim for Linux) is disabled by default, but again, they mandated there must be an easy toggle to enable it. I don't begrudge them to much for it, because there have been multiple instances of SB bypass via 3rd party signed binaries.

All of this is to say: this is not a scenario I'm worried about today. Of course this may change down the line.

Re: Lennart Poettering, Christian Brauner founded a new company

#309
post #170

Earlier quoted context omitted.

The trick is the same: use a popular linux distribution and don't fight the kinks. The people who had no issues with Pulseaudio; used a mainstream distribution. Those distributions did the heavy lifting of making sure stuff fit together in a cohesive way. SystemD is very opinionated, so you'd assume it wouldn't have the same results, but it does.. if you use a popular distro then they've done a lot of the hard work t…

I only use debian pulseaudio I had to fight every single day, with my "exotic" setup of one set of speakers and a headset with pipewire, I've never had to even touch it systemd: yesterday I had a network service on one machine not start up because the IP it was trying to bind to wasn't available yet the dependencies for the .service file didn't/can't express the networking semantics correctly this isn't some hacked u…

Debian is a darling for which I will always love, but it's inability to deal with systemd is one of the prime reasons I left.

I am not seeing these kind of systemd issues with Fedora / RHEL.

It just works

Post reply on HN