Live data from Hacker News

Lennart Poettering, Christian Brauner founded a new company

amutable.com

571–580 of 770 posts

Re: Lennart Poettering, Christian Brauner founded a new company

#571

Well I was wondering when the war on general computing and computer ownership would be carried into the heart of the open source ecosystems. Sure, there are sensible things that could be done with this. But given the background of the people involved, the fact that this is yet another clear profit-first gathering makes me incredibly pessimistic. This pessimism is made worse by reading the answers of the founders here…

I do sort of wonder if there’s room in my life for a small attested device. Like, I could actually see a little room for my bank to say “we don’t know what other programs are running on your device so we can’t actually take full responsibility for transactions that take place originated from your device,” and if I look at it from the bank’s point of view that doesn’t seem unreasonable. Of course, we’ll see if anybody…

I suggested this as a possible solution in another HN thread a while back, but along the lines of "If a bank wants me to have a secure, locked down terminal to do business with them, then they should be the ones forking it over, not commanding control of my owned personal device."

It would quickly get out of hand if every online service started to do the same though. But, if remote device attestation continues to be pushed and we continue to have less and less control and ownership over our devices, I definitely see a world where I now carry two phones. One running something like GrapheneOS, connected to my own self-hosted services, and a separate "approved" phone to interact with public and essential services as they require crap like play integrity, etc.

But at the end of the day, I still fail see why this is even a need. Governments, banks, other entities have been providing services over the web for decades at this point with little issue. Why are we catering to tech illiteracy (by restricting ownership) instead of promoting tech education and encouraging people to both learn, and importantly, take responsibility for their own actions and the consequences of those actions.

"Someone fell for a scam and drained their bank account" isn't a valid reason to start locking down everyone's devices.

Re: Lennart Poettering, Christian Brauner founded a new company

#572
post #366

Earlier quoted context omitted.

PipeWire is like 10 years newer than PulseAudio. It probably had a chance to learn some lessons! IIRC before PulseAudio we had to mess around with ALSA directly (memory hazy, it was a while ago). It could be a bit of a pain.

I installed Gentoo in 2014 and getting PulseAudio working was much easier than ALSA. It was also much better. I get ALSA followed the Unix philosophy of doing one thing but I want my audio mixer to play multiple sounds at once.

Gentoo in 2014 had dmix enabled by default without the need for any user configuration. I know because I was using it.

Re: Lennart Poettering, Christian Brauner founded a new company

#573

Earlier quoted context omitted.

But I'm not having sex with my bank.

You do know what analogies are, right?

So both consent to sex and now one thinks they're entitled to marriage. That's where this inevitably leads, user/customer lock-in and control.

While the bank use case makes a compelling argument, device attestation won't be used for just banks. It's going to be every god damned thing on the internet. Why? Because why the hell not, it further pushes the costs of doing business of banks/MSPs/email providers/cloud services onto the customer and assigns more of the liabilities.

It will also further the digital divide as there will be zero support for devices that fail attestation at any service requiring it. I used to think that the friction against this technology was overblown, but over the last eighteen months I've come to the conclusion that it is going to be a horrible privacy sucking nightmare wrapped in the gold foil of security.

I've been involved in tech a long, long time. The first thing I'm going to do when I retire is start chucking devices. I'm checking-out, none of this is proving to be worth the financial and privacy costs.

Re: Lennart Poettering, Christian Brauner founded a new company

#574

Earlier quoted context omitted.

"Trusted computing boil down to restricting what software I'm allowed to run on hardware I own and use." Remote attestation doesn't do this.

It absolutely does. Emphasis on use . The last thing I need is my bank requiring me to use a Poettering-certified distribution because anything else is "insecure".

You are acting very entitled thinking you can dictate the conditions under which you can connect to other people's computers. This is a "it takes two to tango" situation. I'm sure YOU would refuse to connect to any bank that refuses to use TLS.

Re: Lennart Poettering, Christian Brauner founded a new company

#575
post #573

Earlier quoted context omitted.

You do know what analogies are, right?

So both consent to sex and now one thinks they're entitled to marriage. That's where this inevitably leads, user/customer lock-in and control. While the bank use case makes a compelling argument, device attestation won't be used for just banks. It's going to be every god damned thing on the internet. Why? Because why the hell not, it further pushes the costs of doing business of banks/MSPs/email providers/cloud servi…

"It's going to be every god damned thing on the internet. Why? Because why the hell not"

This is not a persuasive argument.

You are also ignoring the fact that YOU can use remote attestation to verify remote computers are running what they say they are.

"I've been involved in tech a long, long time. The first thing I'm going to do when I retire is start chucking devices. I'm checking-out, none of this is proving to be worth the financial and privacy costs."

You actually sound like you are having a nervous breakdown. Perhaps you should take a vacation.

Re: Lennart Poettering, Christian Brauner founded a new company

#576

Earlier quoted context omitted.

It absolutely does. Emphasis on use . The last thing I need is my bank requiring me to use a Poettering-certified distribution because anything else is "insecure".

You are acting very entitled thinking you can dictate the conditions under which you can connect to other people's computers. This is a "it takes two to tango" situation. I'm sure YOU would refuse to connect to any bank that refuses to use TLS.

No man, there is no tango. "It takes two" doesn't apply when one part is a huge corporation.

Re: Lennart Poettering, Christian Brauner founded a new company

#577

Earlier quoted context omitted.

It's a privacy consideration. If you desire to juggle multiple private profiles on a single device extreme care needs to be taken to ensure that at most one profile (the one tied to your real identity) has access to either attestation or DRM. Or better yet, have both permanently disabled. Hardware fingerprinting in general is a difficult thing to protect from - and in an active probing scenario where two apps try to…

Which is why I personally filed off the VIN from my car's engine.

Why stop at the engine?

Re: Lennart Poettering, Christian Brauner founded a new company

#578

Earlier quoted context omitted.

Can it sets terms on my religious and political views? I'm not speaking about race and sex, you cannot choose them (ok, sex you could in some jurisdictions, and there is difference between sex and gender, please, don't be nitpicky here), but about things I can choose same as I can choose my hardware and software to run. If there is real effective market (which is not in any country on Earth, especially for banks), yo…

You DO understand you can own more than one phone, right? Just use one that isn't rooted as a dedicated banking device and the rooted phone for whatever else you need. You are making life far too hard.

But to have two desktop computers — one attestable and other not — is much more hard than two mobile devices.

And we are discussing this movement here. You know, пive him an inch and he'll take a yard.

Re: Lennart Poettering, Christian Brauner founded a new company

#579
post #337

Earlier quoted context omitted.

I’m not sure I understand the threat model for this. Why would I need to worry about my enclave being identifiable? Or is this a business use case? Or why buy used devices if this is a risk?

I assume the use case here is mostly for backend infrastructure rather than consumer devices. You want to verify that a machine has booted a specific signed image before you release secrets like database keys to it. If you can't attest to the boot state remotely, you don't really know if the node is safe to process sensitive data.

I'm confused. People talking about remote attestation which I thought was used for stuff like SGX. A system in an otherwise untrusted state loads a blob of software into an enclave and attests to that fact.

Whereas the state of the system as a whole immediately after it boots can be attested with secure boot and a TPM sealed secret. No manufacturer keys involved (at least AFAIK).

I'm not actually clear which this is. Are they doing something special for runtime integrity? How are you even supposed to confirm that a system hasn't been compromised? I thought the only realistic way to have any confidence was to reboot it.

Re: Lennart Poettering, Christian Brauner founded a new company

#580

Earlier quoted context omitted.

Android lets you put your own signed keys in on certain phones. For now. The banking apps still won't trust them, though. To add a quote from Lennart himself: "The OS configuration and state (i.e. /etc/ and /var/) must be encrypted, and authenticated before they are used. The encryption key should be bound to the TPM device; i.e system data should be locked to a security concept belonging to the system, not the user.…

Banks do this because they have made their own requirement that the mobile device is a trust root that can authenticate the user. There are better, limited-purpose devices that can do this, but they are not popular/ubiquitous like smartphones, so here we are. The oppressive part of this scheme is that Google's integrity check only passes for _their_ keys, which form a chain of trust through the TEE/TPM, through the b…

Banks do this because they can. If most consumer devices did not support the tech they would not be able to.
Post reply on HN