Live data from Hacker News

Lennart Poettering, Christian Brauner founded a new company

amutable.com

551–560 of 770 posts

Re: Lennart Poettering, Christian Brauner founded a new company

#551

Earlier quoted context omitted.

Can I build my own kernel and still use software that wants attestation?

Do you have a way to tell the software to trust your kernel? If so, yes. Things like the web show how we can achieve distributed trust.

"Trust" has become such an orwellian word in tech.

Re: Lennart Poettering, Christian Brauner founded a new company

#552

Earlier quoted context omitted.

Anonymous-attestation protocols are well known in cryptography, and some are standardized: https://en.wikipedia.org/wiki/Direct_Anonymous_Attestation

But what's it attesting? Their byline "Every system starts in a verified state and stays trusted over time" should be "Every system starts in a verified state of 8,000 yet-to-be-discovered vulns and stays in that vulnerable state over time". The figure is made up but see for example https://tuxcare.com/blog/the-linux-kernel-cve-flood-continue... . So what you're attesting is that all the bugs are still present, not t…

Well, if a rootkit gets installed later, attention might be handy? Or am I missing something?

Re: Lennart Poettering, Christian Brauner founded a new company

#553

Earlier quoted context omitted.

"Ubuntu Core" is a similar product [1] As I understand it, the main customers for this sort of thing are companies making Tivo-style products - where they want to use Linux in their product, but they want to lock it down so it can't be modified by the device owner. This can be pretty profitable; once your customers have rolled out a fleet of hardware locked down to only run kernels you've signed. [1] https://ubuntu.c…

This sounds like a net negative for the end user

Ever seen a default ubuntu splash screen/wallpaper on a train, coffee machine, airport terminal kiosk, bus, or other big piece of slow moving, appliance-y thing?

That is why Ubuntu Core (and similar) exist. More secure, better update strategy, lower net cost. I don't agree with the licensing or pricing model, but there are perfectly good technical reasons to use it.

Re: Lennart Poettering, Christian Brauner founded a new company

#555

Entities other than me being able to control what runs on the device I physically posses is absolutely not acceptable in any way. Screw your clients, screw you shareholders and screw you.

Assuming you're using systemd, you already gave up control over your system. The road to hell was already paved. Now, you would have to go out of your way to retain control.

In the great scheme of things, this period where systemd was intentionally designed and developed and funded to hurt your autonomy but seemed temporarily innocuous will be a rounding error.

Re: Lennart Poettering, Christian Brauner founded a new company

#556

Earlier quoted context omitted.

You are trying to portrait it as an exchange between equal parties which it isn't. I am totally entitled not to have to use a thrid-party-controlled device to access government services. Or my bank account.

remote attestation is just fancy digital signatures with hardware protected secret keys. Are you freaking out about digital signatures used anywhere else?

Trusted computing boil down to restricting what software I'm allowed to run on hardware I own and use. The technical means to do so are irrelevant.

Re: Lennart Poettering, Christian Brauner founded a new company

#557

Earlier quoted context omitted.

anyone who thinks that pipewire - pipewire! - is "a simple solution" understands nothing about pipewire. don't get me wrong, i use pipewire all day every day, and wrote one of the APIs (JACK) that it implements (pretty well, too!). but pipewire is an order of magnitude more complex than pulseaudio.

As an end user hand assembling desktop services on non-Systemd distros (Artix, Devuan, Gentoo, Guix) over the years, and thus had no concern about APIs, Pipewire just works and PulseAudio gave endless trouble. My 0.02 bits.

As another user on Gentoo, pipewire is a never ending pain in the ass full of "magic" behavior and weird bugs. I mostly skipped pulse though so it may be simple in comparison to that.

Re: Lennart Poettering, Christian Brauner founded a new company

#558
post #436
post #367

Please don't bring attestation to common Linux distributions. This technology, by essence, moves trust to a third party distinct of the user. I don't see how it can be useful in any way to end users like most of us here. Its use by corporations has already caused too much damage and exclusion in the mobile landscape, and I don't want folks like us becoming pariahs in our own world, just because we want machines we bo…

Attestation is a critical feature for many H/W companies (e.g. IoT, robotics), and they struggle with finding security engineers who expertise in this area (disclaimer: I used to work as a operating system engineer + security engineer). Many distros are not only designed for desktop users, but also for industrial uses. If distros ship standardized packages in this area, it would help those companies a lot.

> Attestation is a critical feature for many H/W companies

Like John Deere. Read about how they use that sort of thing

Re: Lennart Poettering, Christian Brauner founded a new company

#559

Well I was wondering when the war on general computing and computer ownership would be carried into the heart of the open source ecosystems. Sure, there are sensible things that could be done with this. But given the background of the people involved, the fact that this is yet another clear profit-first gathering makes me incredibly pessimistic. This pessimism is made worse by reading the answers of the founders here…

I do sort of wonder if there’s room in my life for a small attested device. Like, I could actually see a little room for my bank to say “we don’t know what other programs are running on your device so we can’t actually take full responsibility for transactions that take place originated from your device,” and if I look at it from the bank’s point of view that doesn’t seem unreasonable.

Of course, we’ll see if anybody is actually engaging with this idea in good faith when it all gets rolled out. Because the bank has full end-to-end control over the device, authentication will be fully their responsibility and the (basically bullshit in the first place) excuse of “your identity was stolen,” will become not-a-thing.

Obviously I would not pay for such a device (and will always have a general purpose computer that runs my own software), but if the bank or Netflix want to send me a locked down terminal to act as a portal to their services, I guess I would be fine with using it to access (just) their services.

Post reply on HN