Live data from Hacker News

Lennart Poettering, Christian Brauner founded a new company

amutable.com

561–570 of 770 posts

Re: Lennart Poettering, Christian Brauner founded a new company

#561

Entities other than me being able to control what runs on the device I physically posses is absolutely not acceptable in any way. Screw your clients, screw you shareholders and screw you.

Assuming you're using systemd, you already gave up control over your system. The road to hell was already paved. Now, you would have to go out of your way to retain control. In the great scheme of things, this period where systemd was intentionally designed and developed and funded to hurt your autonomy but seemed temporarily innocuous will be a rounding error.

Nah man, yo are FUDing. systemd might have some poor design choices and arrogant maintainers, but at least I can drop it at any time and my bank wouldn't freak out about it. This one… It's a whole another level.

Re: Lennart Poettering, Christian Brauner founded a new company

#562

Earlier quoted context omitted.

There were dozens of other init systems that, like systemd, wasn't a shell script. What set systemd apart is the collection of tightly integrated utilities such as a dns resolver, sntp client, core dump handler, rpc-like api linking to complex libraries in the hot path and so on and so forth that has been a constant stream of security exploits for over a decade now. This is a case where the critics were proven to be…

As predicted. I thought pulseaudio should have been enough of a lesson. Besides that, any person that works on open source but that joins Microsoft is not in the camp that should have a say in the overall direction of Linux.

"People don't learn lessons" is a lesson that people don't learn.

Re: Lennart Poettering, Christian Brauner founded a new company

#563

Earlier quoted context omitted.

Assuming you're using systemd, you already gave up control over your system. The road to hell was already paved. Now, you would have to go out of your way to retain control. In the great scheme of things, this period where systemd was intentionally designed and developed and funded to hurt your autonomy but seemed temporarily innocuous will be a rounding error.

Nah man, yo are FUDing. systemd might have some poor design choices and arrogant maintainers, but at least I can drop it at any time and my bank wouldn't freak out about it. This one… It's a whole another level.

I don't think Mr Pottering was brought by accident, maybe his decade of contribution making sure systemd services can be manipulated by a supervisor (in the case of wsl and ms) is a valuable asset. Systemd don't even need to change much to become the devil itself, it just have to upstream merge changes already consolidated in the past 5 years or so... But logically it's safe because for this to become a problem systemd would have to be adopted by the majority of distributions and its maintainers would have to concede to the pressure of big corps and such...oh, wait

Re: Lennart Poettering, Christian Brauner founded a new company

#564

Earlier quoted context omitted.

remote attestation is just fancy digital signatures with hardware protected secret keys. Are you freaking out about digital signatures used anywhere else?

Trusted computing boil down to restricting what software I'm allowed to run on hardware I own and use. The technical means to do so are irrelevant.

"Trusted computing boil down to restricting what software I'm allowed to run on hardware I own and use." Remote attestation doesn't do this.

Re: Lennart Poettering, Christian Brauner founded a new company

#565

What is the endgame here? Obviously "heightened security" in some kind of sense, but to what end and what mechanisms? What is the scope of the work? Is this work meant to secure forges and upstream development processes via more rigid identity verification, or package manager and userspace-level runtime restrictions like code signing? Will there be a push to integrate this work into distributions, organizations, or t…

Personally for me this is interesting because there needs to be a way where a hardware token providing an identity should interact with a device and software combination which would ensure no tampering between the user who owns the identity and the end result of computing is. A concrete example of that is electronic ballots, which is a topic I often bump heads with the rest of HN about, where a hardware identity toke…

No.

Re: Lennart Poettering, Christian Brauner founded a new company

#566
post #532
post #402

Earlier quoted context omitted.

> Attestation, secure enclaves, and other technologies create ways to distribute software that otherwise wouldn't exist. How many things are in the cloud solely to enforce access control? What if they didn't have to be? To be honest, mainly companies need that. personal users do not need that. And additionally companies are NOT restrained by governments not to exploit customers as much as possible. So... i also see i…

additionally: > This potential shouldn't prevent our inventing new kinds of tool. Why do i see someone who wants to build an atomic bomb for shit and giggles using this argument, too? As hyperbole as my argument is, the argument given is not good here, as well. The immutable linux people build tools, without building good tools which actually make it easier for private people at home to adapt a immutable linux to THE…

The atomic bomb is good example of what I'm talking about. The reason we haven't had a world war in 80 years is the atomic bomb. Far from being an instrument of misery, it's given us an age of unprecedented peace and prosperity. Plus, all the anti-nuclear activism in the world hasn't come one step closer to banishing nuclear weapons from the earth.

In my personal philosophy, it is never bad to develop a new technology.

Re: Lennart Poettering, Christian Brauner founded a new company

#567
post #565

Earlier quoted context omitted.

Personally for me this is interesting because there needs to be a way where a hardware token providing an identity should interact with a device and software combination which would ensure no tampering between the user who owns the identity and the end result of computing is. A concrete example of that is electronic ballots, which is a topic I often bump heads with the rest of HN about, where a hardware identity toke…

No.

Why not? Being terse does not make one right...

Re: Lennart Poettering, Christian Brauner founded a new company

#568

Earlier quoted context omitted.

Trusted computing boil down to restricting what software I'm allowed to run on hardware I own and use. The technical means to do so are irrelevant.

"Trusted computing boil down to restricting what software I'm allowed to run on hardware I own and use." Remote attestation doesn't do this.

It absolutely does. Emphasis on use. The last thing I need is my bank requiring me to use a Poettering-certified distribution because anything else is "insecure".

Re: Lennart Poettering, Christian Brauner founded a new company

#570
post #296

Earlier quoted context omitted.

PipeWire is like 10 years newer than PulseAudio. It probably had a chance to learn some lessons! IIRC before PulseAudio we had to mess around with ALSA directly (memory hazy, it was a while ago). It could be a bit of a pain.

I remember ALSA. Sure, it was finnicky to use `alsamixer` to unmute the master channels now and then, but I personally never had any trouble with it.

I still need to use alsamixer to unmute my headphones after accidentally unplugging them and plugging them in again fails to do so. That's with PipeWire - never had that problem with just ALSA.
Post reply on HN