Live data from Hacker News

Lennart Poettering, Christian Brauner founded a new company

amutable.com

541–550 of 770 posts

Re: Lennart Poettering, Christian Brauner founded a new company

#542
post #18

Earlier quoted context omitted.

The events includes a conference title "Remote Attestation of Imutable Operating Systems built on systemd", which is a bit of a clue.

I'm sure this company is more focused on the enterprise angle, but I wonder if the buildout of support for remote attestation could eventually resolve the Linux gaming vs. anti-cheat stalemate. At least for those willing to use a "blessed" kernel provided by Valve or whoever.

I would rather have it unresolved forever.

Re: Lennart Poettering, Christian Brauner founded a new company

#543

Trusted computing and remote attestation is like two people who want to have sex requiring clean STD tests first. Either party can refuse and thus no sex will happen. A bank trusting a random rooted smartphone is like having sex with a prostitute with no condom. The anti-attestation position is essentially "I have a right to connect to your service with an unverified system, and refusing me is oppression." Translate…

You are trying to portrait it as an exchange between equal parties which it isn't. I am totally entitled not to have to use a thrid-party-controlled device to access government services. Or my bank account.

Re: Lennart Poettering, Christian Brauner founded a new company

#544

Earlier quoted context omitted.

Banks don't use these things because they provide any real security. They use them because the platform company calls it a "security feature" and banks add "security features" to their checklists. The way you defeat things like that is through political maneuvering and guile rather than submission to their artificial narrative. Publish your own papers and documentation that recommends apps not support any device with…

Remote attestation absolutely provides increased security. Mobile banking fraud rates are substantially lower than desktop/browser banking fraud. Attestation is major reason why. I think ever compute professional needs to spend at least a year trying to secure a random companies windows network to appreciate how impossible this actually is without hardware based roots of trust like TPMs and HSMs

>Attestation is major reason why.

It's not. Mobile applications just don't have unrestricted access to everything in your user directory, attestation have nothing to do with it.

Re: Lennart Poettering, Christian Brauner founded a new company

#545
post #534

Earlier quoted context omitted.

This is the problem with Linux in general. It's way too much infiltrated by our adversaries from big tech industry. Look at all the kernel patch submissions. 90% are not users but big tech drones. Look at the Linux foundation board. It's the who's who of big tech. This is why I moved to the BSDs. Linux started as a grassroots project but turned commercial, the BSDs started commercial but are hardly still used as such…

As a complete guess, I would say that 90% of Linux systems are run by "big tech drones". And also by small companies using technology. Open source operating systems are not a zero sum game. Yes there is a certain gravitational pull from all the work contributed by the big companies. If you aren't contributing "for-hire", then you choose what you want to work on, and what you want to use.

Only if you count Android phones as being run by Google ... which is exactly the problem we want to avoid with our PCs.

Re: Lennart Poettering, Christian Brauner founded a new company

#546

Earlier quoted context omitted.

This is the problem with Linux in general. It's way too much infiltrated by our adversaries from big tech industry. Look at all the kernel patch submissions. 90% are not users but big tech drones. Look at the Linux foundation board. It's the who's who of big tech. This is why I moved to the BSDs. Linux started as a grassroots project but turned commercial, the BSDs started commercial but are hardly still used as such…

Linux has been majority developed by large tech companies for the last 20+ years. If not for them, it would not be anywhere close to where it is today. You may not like this fact, but it's not really a new development nor something that can be described as infiltration. At the end of the day, maintaining software without being paid to do so is not generally sustainable.

Considering some of the changes to the ecosystem in the last 20 years it's not clear that this has made things better.

Re: Lennart Poettering, Christian Brauner founded a new company

#547

Earlier quoted context omitted.

I'm not too big in this field but didn't many of those same IOT companies and the like struggle with the packages becoming dependent on Poeterings work since they often needed much smaller/minimal distros?

I don't think this is generally true. If you are running Linux in your stack, your device probably is investing in 1GiB+ RAM and 2GiB+ of flash storage. systemd et al are not a problem at that point. Running a UI will end up being considerably more costly.

I can assure you there are many Linux devices with specs significantly lower than that.

Re: Lennart Poettering, Christian Brauner founded a new company

#548
post #51

This seems like the kind of technology that could make the problem described in https://www.gnu.org/philosophy/can-you-trust.en.html a lot worse. Do you have any plans for making sure it doesn't get used for that?

I'm Aleksa, one of the founding engineers. We will share more about this in the coming months but this is not the direction nor intention of what we are working on. The models we have in mind for attestation are very much based on users having full control of their keys. This is not just a matter of user freedom, in practice being able to do this is far more preferable for enterprises with strict security controls. I…

> I've been a FOSS guy my entire adult life, I wouldn't put my name to something that would enable the kinds of issues you describe.

The road to hell is paved with good intentions.

Re: Lennart Poettering, Christian Brauner founded a new company

#549

Earlier quoted context omitted.

> the plan seems to be to replace package management with image based whole dist a/b swaps The plan is probably to have that as an alternative for the niche uses where that is appropriate. This majority of this thread seems to have slid on that slippery slope, and jumped directly to the conclusion where the attestation mechanism will be mandatory on all linux machines in the world and you won't be able to run anythin…

Nobody says that you will not have alternatives. What people are saying, is that if you're using those alternatives you won't be able to watch videos online, or access your bank account. Eventually you will not be able to block ads.

> Nobody says that you will not have alternatives

Maybe you want to reread through this thread.

> Eventually you will not be able to block ads.

That's so far down the slippery slope and with so many other things that need to go wrong that I'm not worried and I'm willing to be the one to get "told you so" if it happens.

Re: Lennart Poettering, Christian Brauner founded a new company

#550

Trusted computing and remote attestation is like two people who want to have sex requiring clean STD tests first. Either party can refuse and thus no sex will happen. A bank trusting a random rooted smartphone is like having sex with a prostitute with no condom. The anti-attestation position is essentially "I have a right to connect to your service with an unverified system, and refusing me is oppression." Translate…

You are trying to portrait it as an exchange between equal parties which it isn't. I am totally entitled not to have to use a thrid-party-controlled device to access government services. Or my bank account.

remote attestation is just fancy digital signatures with hardware protected secret keys. Are you freaking out about digital signatures used anywhere else?
Post reply on HN