Live data from Hacker News

Lennart Poettering, Christian Brauner founded a new company

amutable.com

311–320 of 770 posts

Re: Lennart Poettering, Christian Brauner founded a new company

#311

Earlier quoted context omitted.

I only use debian pulseaudio I had to fight every single day, with my "exotic" setup of one set of speakers and a headset with pipewire, I've never had to even touch it systemd: yesterday I had a network service on one machine not start up because the IP it was trying to bind to wasn't available yet the dependencies for the .service file didn't/can't express the networking semantics correctly this isn't some hacked u…

I can totally relate to this, it's gotten to the point that I'm just as scared of rebooting my Linux boxes as I was of rebooting my windows machine a couple of decades ago. And quite probably more scared.

What distro?

Re: Lennart Poettering, Christian Brauner founded a new company

#313
post #294

Earlier quoted context omitted.

What are you talking about? This has nothing to do with general purpose computing and everything to do with allowing you to authenticate the parts of the Linux boot process that must by necessity be left unencrypted in order to actually boot your computer. This is putting SecureBoot and the TPM to work for your benefit. It's not propaganda in any sense, it's recognizing that Linux is behind the state of the art compa…

Secure boot is initialized by the first person who physically touches the computer and wants to initialize it. Guess who that is? Hint: it's not the final owner. It's only secure from evil maker attacks if it can be wiped and reinitialised at any time.

You seem to be under the impression that you cannot reset your Secure Boot to setup mode. You can in the UEFI, doing so wipes any enrolled keys. This, of course assumes you trust the UEFI (and hardware) vendors. But if you don't, you have much bigger problems anyway.

Is it possible someone will eventually build a system that doesn't allow this? Yes. Is this influenced in any way by features of Linux software? No.

Re: Lennart Poettering, Christian Brauner founded a new company

#315
post #221

Earlier quoted context omitted.

No personal attacks on HN, please. https://news.ycombinator.com/newsguidelines.html

This is relevant. Every project he's worked on has been a dumpster fire. systemd sucks. PulseAudio sucks. GNOME sucks. Must the GP list out all the ways in which they suck to make it a more objective attack?

This is not about the person being attacked, it's about what this kind of thing does to us as a community. It's not what the site is for, and destroys what it is for.

Re: Lennart Poettering, Christian Brauner founded a new company

#317
post #118
post #86

Earlier quoted context omitted.

Damn, you are thirsty! Are these some problems you've personally been dealing with?

I just want more trustworthy systems. This particular concept of combining reproducible builds, remote attestation and transparency logs is something I came up with in 2018. My colleagues and I started working on it, took a detour into hardware (tillitis.se) and kind of got stuck on the transparency part (sigsum.org, transparency.dev, witness-network.org). Then we discovered snapshot.debian.org wasn't feeling well, s…

This appears to be the only comment worth reading. Thanks.

Re: Lennart Poettering, Christian Brauner founded a new company

#318
Shall it be backdoorable like systemd-enabled distro nearly had a backdoorable SSH? For non-systemd distro weren't affected.

Why should we trust microsofties to produce something secure and non-backdoored?

And, lastly, why should Linux's security be tied to a private company? Oooh, but it's of course not about security: it's about things like DRM.

I hope Linus doesn't get blinded here: systemd managed to get PID 1 on many distros but they thankfully didn't manage, yet, to control the kernel. I hope this project ain't the final straw to finally meddle into the kernel.

Currently I'm doing:

    Proxmox / systemd-less VMs / containers
But Promox is Debian based and Debian really drank too much of the systemd koolaid.

So my plan is:

    FreeBSD / bhyve hypervisor / systemd-less Linux VMs / containers
And then I'll be, at long last, systemd-free again.

This project is an attack on general-purpose computing.

Re: Lennart Poettering, Christian Brauner founded a new company

#319
post #51

Earlier quoted context omitted.

I'm Aleksa, one of the founding engineers. We will share more about this in the coming months but this is not the direction nor intention of what we are working on. The models we have in mind for attestation are very much based on users having full control of their keys. This is not just a matter of user freedom, in practice being able to do this is far more preferable for enterprises with strict security controls. I…

This is extremely bad logic. The technology of enforcing trusted software is without inherent value good or ill depending entirely on expected usage. Anything that is substantially open will be used according to the values of its users not according to your values so we ought instead to consider their values not yours. Suppose you wanted to identify potential agitators by scanning all communication for indications in…

[deleted]

Re: Lennart Poettering, Christian Brauner founded a new company

#320

systemd solved/improved a bunch of things for linux, but now the plan seems to be to replace package management with image based whole dist a/b swaps. and to have signed unified kernel images. this basically will remove or significantly encumber user control over their system, such that any modification will make you loose your "signed" status and ... boom! goodbye accessing the internet without an id pottering recen…

> this basically will remove or significantly encumber user control over their system, such that any modification will make you loose your "signed" status and ... boom! goodbye accessing the internet without an id

Yeah. I'm pretty sure it requires a very specific psychological profile to decide to work on such a user-hostile project while post-fact rationalizing that it's "for good".

All I can say is I'm not surprised that Poettering is involved in such a user-hostile attack on free computing.

P.S: I don't care about the downvotes, you shouldn't either.

Post reply on HN