Live data from Hacker News

Lennart Poettering, Christian Brauner founded a new company

amutable.com

451–460 of 770 posts

Re: Lennart Poettering, Christian Brauner founded a new company

#451

Earlier quoted context omitted.

Anonymous-attestation protocols are well known in cryptography, and some are standardized: https://en.wikipedia.org/wiki/Direct_Anonymous_Attestation

> Anonymous-attestation protocols are well known in cryptography, and some are standardized: https://en.wikipedia.org/wiki/Direct_Anonymous_Attestation Which does exactly what I said. Full zero knowledge attestation isn't practical as a single compromised key would give rise to a service that would serve everyone. The solution first adopted by the TCG (TPM specification v1.1) required a trusted third-party, namely a…

Apple uses Blind Signatures for attestation. It's how they avoid captchas at CloudFlare and Fastly in their Private Relay product

https://educatedguesswork.org/posts/private-access-tokens/

Re: Lennart Poettering, Christian Brauner founded a new company

#452

Trusted computing and remote attestation is like two people who want to have sex requiring clean STD tests first. Either party can refuse and thus no sex will happen. A bank trusting a random rooted smartphone is like having sex with a prostitute with no condom. The anti-attestation position is essentially "I have a right to connect to your service with an unverified system, and refusing me is oppression." Translate…

But I'm not having sex with my bank.

Re: Lennart Poettering, Christian Brauner founded a new company

#453
post #51

This seems like the kind of technology that could make the problem described in https://www.gnu.org/philosophy/can-you-trust.en.html a lot worse. Do you have any plans for making sure it doesn't get used for that?

I'm Aleksa, one of the founding engineers. We will share more about this in the coming months but this is not the direction nor intention of what we are working on. The models we have in mind for attestation are very much based on users having full control of their keys. This is not just a matter of user freedom, in practice being able to do this is far more preferable for enterprises with strict security controls. I…

Thanks for the clarification and to be clear, I don't doubt your personal intent or FOSS background. The concern isn't bad actors at the start, it's how projects evolve once they matter.

History is pretty consistent here:

WhatsApp: privacy-first, founders with principles, both left once monetization and policy pressure kicked in.

Google: 'Don’t be evil' didn’t disappear by accident — it became incompatible with scale, revenue, and government relationships.

Facebook/Meta: years of apologies and "we'll do better," yet incentives never changed.

Mobile OS attestation (iOS / Android): sold as security, later became enforcement and gatekeeping.

Ruby on Rails ecosystem: strong opinions, benevolent control, then repeated governance, security, and dependency chaos once it became critical infrastructure. Good intentions didn't prevent fragility, lock-in, or downstream breakage.

Common failure modes:

Enterprise customers demand guarantees - policy creeps in.

Governments demand compliance - exceptions appear.

Liability enters the picture - defaults shift to "safe for the company."

Revenue depends on trust decisions - neutrality erodes.

Core maintainers lose leverage - architecture hardens around control.

Even if keys are user-controlled today, the key question is architectural: Can this system resist those pressures long-term, or does it merely promise to?

Most systems that can become centralized eventually do, not because engineers change, but because incentives do. That’s why skepticism here isn't personal — it's based on pattern recognition.

I genuinely hope this breaks the cycle. History just suggests it's much harder than it looks.

Re: Lennart Poettering, Christian Brauner founded a new company

#454

The photos depict these people as funny hobbits :D. Photographer trolled them big time. Now, the only question left is whether their feet are hairy. --- Making secure boot 100 times simpler would be a deffo plus.

I'm not seeing any big problems with the portraits.

Having said that, should this company not be successful, Mr Zbyszek Jędrzejewski-Szmek has potentially a glowing career as an artists' model. Think Rembrandt sketches.

I look forward to something like ChromeOS that you can just install on any old refurbished laptop. But I think the money is in servers.

Re: Lennart Poettering, Christian Brauner founded a new company

#455

Earlier quoted context omitted.

Hi Daan, Thanks for the answer. Let me ask you something close with a more blunt angle: Considering most of the tech is already present and shipping in the current systemd, what prevents our systems to become a immutable monolith like macOS or current Android with the flick of a switch? Or a more grave scenario: What prevents Microsoft from mandating removal of enrollment permissions for user keychains and Secure Boo…

So adding all of this technology will certainly make it more easy to be used for either good or bad. And it will certainly become possible to build an OS that will be less hackable than your run of the mill Linux distro. But we will never enforce using any of these features in systemd itself. It will always be up to the distro to enable and configure the system to become an immutable monolith. And I certainly don't t…

Building stuff like this is wrong. You should find a different job.

Re: Lennart Poettering, Christian Brauner founded a new company

#456

Earlier quoted context omitted.

see latest "MS just divilged disk encryption keys to govt" news to see why this is a horrid idea

I’m skeptical about the push toward third-party hardware attestation for Linux kernels. Handing kernel trust to external companies feels like repeating mistakes we’ve already seen with iOS and Android, where security mechanisms slowly turned into control mechanisms. Centralized trust Hardware attestation run by third parties creates a single point of trust (and failure). If one vendor controls what’s “trusted,” Linux…

I can see usefulness if the flow was "the device is unlocked by default, there are no keys/certs on it, and it can be reset to that state (for re-use purpose)"

Then the user can put their own key there (if say corporate policies demand it), but there is no 3rd party that can decide what the device can do.

But having 3rd party (and US one too!) that is root of all trust is a massive problem.

Re: Lennart Poettering, Christian Brauner founded a new company

#457

Hello Chris, I am glad to see these efforts are now under an independent firm rather than being directed by Microsoft. What is the ownership structure like? Where/who have you received funding from, and what is the plan for ongoing monetization of your work? Would you ever sell the company to Microsoft, Google, or Amazon? Thanks.

> Where/who have you received funding from

I don't think you will ever get a response to that

Re: Lennart Poettering, Christian Brauner founded a new company

#458

So much negativity in this thread. I actually think this could be useful, because tamper-proof computer systems are useful to prevent evil maid attacks. Especially in the age of Pegasus and other spyware, we should also take physical attack vectors into account. I can relate to people being rather hostile to the idea of boot verification, because this is a process that is really low level and also something that we a…

I personally do not worry about an evil maid attack _at all_. But I do worry about someone restricting what I can do with _my_ computer.

I mean, in theory, the idea is great. But it WILL be misused by greedy fucks.

Re: Lennart Poettering, Christian Brauner founded a new company

#460
post #436
post #367

Please don't bring attestation to common Linux distributions. This technology, by essence, moves trust to a third party distinct of the user. I don't see how it can be useful in any way to end users like most of us here. Its use by corporations has already caused too much damage and exclusion in the mobile landscape, and I don't want folks like us becoming pariahs in our own world, just because we want machines we bo…

Attestation is a critical feature for many H/W companies (e.g. IoT, robotics), and they struggle with finding security engineers who expertise in this area (disclaimer: I used to work as a operating system engineer + security engineer). Many distros are not only designed for desktop users, but also for industrial uses. If distros ship standardized packages in this area, it would help those companies a lot.

I'm not too big in this field but didn't many of those same IOT companies and the like struggle with the packages becoming dependent on Poeterings work since they often needed much smaller/minimal distros?
Post reply on HN