Entities other than me being able to control what runs on the device I physically posses is absolutely not acceptable in any way. Screw your clients, screw you shareholders and screw you.
Assuming you're using systemd, you already gave up control over your system. The road to hell was already paved. Now, you would have to go out of your way to retain control. In the great scheme of things, this period where systemd was intentionally designed and developed and funded to hurt your autonomy but seemed temporarily innocuous will be a rounding error.
Lennart Poettering, Christian Brauner founded a new company
561–570 of 770 posts
Re: Lennart Poettering, Christian Brauner founded a new company
#562Earlier quoted context omitted.
There were dozens of other init systems that, like systemd, wasn't a shell script. What set systemd apart is the collection of tightly integrated utilities such as a dns resolver, sntp client, core dump handler, rpc-like api linking to complex libraries in the hot path and so on and so forth that has been a constant stream of security exploits for over a decade now. This is a case where the critics were proven to be…
As predicted. I thought pulseaudio should have been enough of a lesson. Besides that, any person that works on open source but that joins Microsoft is not in the camp that should have a say in the overall direction of Linux.
Re: Lennart Poettering, Christian Brauner founded a new company
#563Earlier quoted context omitted.
Assuming you're using systemd, you already gave up control over your system. The road to hell was already paved. Now, you would have to go out of your way to retain control. In the great scheme of things, this period where systemd was intentionally designed and developed and funded to hurt your autonomy but seemed temporarily innocuous will be a rounding error.
Nah man, yo are FUDing. systemd might have some poor design choices and arrogant maintainers, but at least I can drop it at any time and my bank wouldn't freak out about it. This one… It's a whole another level.
Re: Lennart Poettering, Christian Brauner founded a new company
#564Earlier quoted context omitted.
remote attestation is just fancy digital signatures with hardware protected secret keys. Are you freaking out about digital signatures used anywhere else?
Trusted computing boil down to restricting what software I'm allowed to run on hardware I own and use. The technical means to do so are irrelevant.
Re: Lennart Poettering, Christian Brauner founded a new company
#565What is the endgame here? Obviously "heightened security" in some kind of sense, but to what end and what mechanisms? What is the scope of the work? Is this work meant to secure forges and upstream development processes via more rigid identity verification, or package manager and userspace-level runtime restrictions like code signing? Will there be a push to integrate this work into distributions, organizations, or t…
Personally for me this is interesting because there needs to be a way where a hardware token providing an identity should interact with a device and software combination which would ensure no tampering between the user who owns the identity and the end result of computing is. A concrete example of that is electronic ballots, which is a topic I often bump heads with the rest of HN about, where a hardware identity toke…
Re: Lennart Poettering, Christian Brauner founded a new company
#566Earlier quoted context omitted.
> Attestation, secure enclaves, and other technologies create ways to distribute software that otherwise wouldn't exist. How many things are in the cloud solely to enforce access control? What if they didn't have to be? To be honest, mainly companies need that. personal users do not need that. And additionally companies are NOT restrained by governments not to exploit customers as much as possible. So... i also see i…
additionally: > This potential shouldn't prevent our inventing new kinds of tool. Why do i see someone who wants to build an atomic bomb for shit and giggles using this argument, too? As hyperbole as my argument is, the argument given is not good here, as well. The immutable linux people build tools, without building good tools which actually make it easier for private people at home to adapt a immutable linux to THE…
In my personal philosophy, it is never bad to develop a new technology.
Re: Lennart Poettering, Christian Brauner founded a new company
#567Earlier quoted context omitted.
Personally for me this is interesting because there needs to be a way where a hardware token providing an identity should interact with a device and software combination which would ensure no tampering between the user who owns the identity and the end result of computing is. A concrete example of that is electronic ballots, which is a topic I often bump heads with the rest of HN about, where a hardware identity toke…
No.
Re: Lennart Poettering, Christian Brauner founded a new company
#568Earlier quoted context omitted.
Trusted computing boil down to restricting what software I'm allowed to run on hardware I own and use. The technical means to do so are irrelevant.
"Trusted computing boil down to restricting what software I'm allowed to run on hardware I own and use." Remote attestation doesn't do this.
Re: Lennart Poettering, Christian Brauner founded a new company
#569Earlier quoted context omitted.
No.
Why not? Being terse does not make one right...
Re: Lennart Poettering, Christian Brauner founded a new company
#570Earlier quoted context omitted.
PipeWire is like 10 years newer than PulseAudio. It probably had a chance to learn some lessons! IIRC before PulseAudio we had to mess around with ALSA directly (memory hazy, it was a while ago). It could be a bit of a pain.
I remember ALSA. Sure, it was finnicky to use `alsamixer` to unmute the master channels now and then, but I personally never had any trouble with it.