Live data from Hacker News

Lennart Poettering, Christian Brauner founded a new company

amutable.com

491–500 of 770 posts

Re: Lennart Poettering, Christian Brauner founded a new company

#491
post #158

Earlier quoted context omitted.

You think? It took us nearly a decade and a half to unfuck the pulseaudio situation and finally arrive at a simple solution (pipewire). SystemD has a lot more people refining it down but a clean (under the hood) implementation probably won't be witnessed in my lifetime.

anyone who thinks that pipewire - pipewire! - is "a simple solution" understands nothing about pipewire. don't get me wrong, i use pipewire all day every day, and wrote one of the APIs (JACK) that it implements (pretty well, too!). but pipewire is an order of magnitude more complex than pulseaudio.

[deleted]

Re: Lennart Poettering, Christian Brauner founded a new company

#492
post #158

Earlier quoted context omitted.

You think? It took us nearly a decade and a half to unfuck the pulseaudio situation and finally arrive at a simple solution (pipewire). SystemD has a lot more people refining it down but a clean (under the hood) implementation probably won't be witnessed in my lifetime.

anyone who thinks that pipewire - pipewire! - is "a simple solution" understands nothing about pipewire. don't get me wrong, i use pipewire all day every day, and wrote one of the APIs (JACK) that it implements (pretty well, too!). but pipewire is an order of magnitude more complex than pulseaudio.

As an end user hand assembling desktop services on non-Systemd distros (Artix, Devuan, Gentoo, Guix) over the years, and thus had no concern about APIs, Pipewire just works and PulseAudio gave endless trouble.

My 0.02 bits.

Re: Lennart Poettering, Christian Brauner founded a new company

#493

Earlier quoted context omitted.

I think at some point we will see a steep increase in value of old hardware that can still run unsigned binaries.

It won't be able to interact with any online services like Google or Hacker News.

Ah, we will get more done. Or maybe just see you on the mailing list and IRC?!

Re: Lennart Poettering, Christian Brauner founded a new company

#494

systemd solved/improved a bunch of things for linux, but now the plan seems to be to replace package management with image based whole dist a/b swaps. and to have signed unified kernel images. this basically will remove or significantly encumber user control over their system, such that any modification will make you loose your "signed" status and ... boom! goodbye accessing the internet without an id pottering recen…

> the plan seems to be to replace package management with image based whole dist a/b swaps

The plan is probably to have that as an alternative for the niche uses where that is appropriate.

This majority of this thread seems to have slid on that slippery slope, and jumped directly to the conclusion where the attestation mechanism will be mandatory on all linux machines in the world and you won't be able to run anything without. Which even if it would be a purpose for amutable as a company, it's unfeasible to do when there's such a breadth of distributions and non corpo affiliated developers out there that would need to cooperate for that to happen.

Re: Lennart Poettering, Christian Brauner founded a new company

#495
post #470
post #367

Please don't bring attestation to common Linux distributions. This technology, by essence, moves trust to a third party distinct of the user. I don't see how it can be useful in any way to end users like most of us here. Its use by corporations has already caused too much damage and exclusion in the mobile landscape, and I don't want folks like us becoming pariahs in our own world, just because we want machines we bo…

A silver lining, is it would likely be attempted via systemd. This may finally be enough to kick off a fork, and get rid of all the silly parts of it. To anyone thinking not possibile, we already switched inits to systemd. And being persnickety saw mariadb replace mysql everywhere, libreoffice replace open office, and so on. All the recent pushiness by a certain zealotish Italian debian maintainer, only helps this ca…

> A silver lining, is it would likely be attempted via systemd. This may finally be enough to kick off a fork, and get rid of all the silly parts of it.

This misunderstands why systemd succeeded. It included several design decisions aimed at easing distribution maintainers' burdens, thus making adoption attractive to the same people that would approve this adoption.

If a systemd fork differentiates on not having attestation and getting rid of an unspecified set of "all the silly parts", how would they entice distro maintainers to adopt it? Elaborating what is meant by "silly parts" would be needed to answer that question.

Re: Lennart Poettering, Christian Brauner founded a new company

#496

Earlier quoted context omitted.

Secure Boot only extends the chain of trust from your firmware down the first UEFI binary it loads. Currently SB is effectively useless because it will at best authenticate your kernel but the initrd and subsequent userspace (including programs that run as root) are unverified and can be replaced by malicious alternatives. Secure Boot as it stands right now in the Linux world is effectively an annoyance that’s only t…

A basic setup to make use of secure boot is SB+TPM+LUKS. Unfortunately I don't know of any distro that offers this in a particularly robust way. Code signature verification is an interesting idea, but I'm not sure how it could be achieved. Have distro maintainers sign the code?

> A basic setup to make use of secure boot is SB+TPM+LUKS. Unfortunately I don't know of any distro that offers this in a particularly robust way.

Have a look at Ubuntu Core 24 and later. Though it's not exactly a desktop system, but rathe oriented towards embedded/appliances. Recent Ubuntu desktop (from 25.04 IIRC) started getting the same mechanism gradually integrated in each release. Upcoming Ubuntu 26.04 is expected to support TPM backed FDE. Worth a try if you can set up a VM with a software TPM.

Keep in mind though, there's been plenty of issues with various EFI firmwares, especially on the appliances side. EFI specs are apparently treated as guidelines rather than actual specification by whoever ends up implementing the firmware.

Re: Lennart Poettering, Christian Brauner founded a new company

#497

Earlier quoted context omitted.

> I've been a FOSS guy my entire adult life, I wouldn't put my name to something that would enable the kinds of issues you describe. Until you get acquired, receive a golden parachute and use it when realizing that the new direction does not align with your views anymore. But, granted, if all you do is FOSS then you will anyway have a hard time keeping evil actors from using your tech for evil things. Might as well g…

You could tell this sort of insinuation to anyone. Including you. Argument should be technical.

> You could tell this sort of insinuation to anyone. Including you.

Yes. You correctly stated the important point.

Re: Lennart Poettering, Christian Brauner founded a new company

#498

What is the endgame here? Obviously "heightened security" in some kind of sense, but to what end and what mechanisms? What is the scope of the work? Is this work meant to secure forges and upstream development processes via more rigid identity verification, or package manager and userspace-level runtime restrictions like code signing? Will there be a push to integrate this work into distributions, organizations, or t…

Personally for me this is interesting because there needs to be a way where a hardware token providing an identity should interact with a device and software combination which would ensure no tampering between the user who owns the identity and the end result of computing is.

A concrete example of that is electronic ballots, which is a topic I often bump heads with the rest of HN about, where a hardware identity token (an electronic ID provided by the state) can be used to participate in official ballots, while both the citizen and the state can have some assurance that there was nothing interceding between them in a malicious way.

Does that make sense?

Re: Lennart Poettering, Christian Brauner founded a new company

#499

Earlier quoted context omitted.

If you're going to flame it you might as well point out something concrete you don't like about it.

"The OS configuration and state (i.e. /etc/ and /var/) must be encrypted, and authenticated before they are used. The encryption key should be bound to the TPM device; i.e system data should be locked to a security concept belonging to the system, not the user." See Android; or, where you no longer own your device, and if the company decides, you no longer own your data or access to it.

I mentioned it somewhere else in the thread, and btw, I'm not affiliated with the company, this is just my charitable interpretation of their intentions: this is not for requiring _every_ consumer linux device to have attestation, but for specific devices that are needed for niche purposes to have a method to use an open OS stack while being capable of attestation.

Re: Lennart Poettering, Christian Brauner founded a new company

#500
Well I was wondering when the war on general computing and computer ownership would be carried into the heart of the open source ecosystems.

Sure, there are sensible things that could be done with this. But given the background of the people involved, the fact that this is yet another clear profit-first gathering makes me incredibly pessimistic.

This pessimism is made worse by reading the answers of the founders here in this thread: typical corporate talk. And most importantly: preventing the very real dangers involved is clearly not a main goal, but is instead brushed off with empty platitudes like "I've been a FOSS guy my entire adult life...." instead of describing or considering actual preventive measures. And even if the claim was true, the founders had a real love for the hacker spirit, there is obviously nothing stopping them from selling to the usual suspects and golden parachute out.

I was really struggling to not make this comment just another snarky, sarcastic comment, but it is exhausting. It is exhausting to see the hatred some have for people just owning their hardware. So sorry, "don't worry, we're your friends" just doesn't cut it to come at this with a positive attitude.

The benefits are few, the potential to do a lot of harm is large. And the people involved clearly have the network and connections to make this an instrument of user-hostility.

Post reply on HN