Earlier quoted context omitted.
> [T]he war on general computing and computer ownership [...] It is exhausting to see the hatred some have for people just owning their hardware. The integrity of a system being verified/verifiable doesn't imply that the owner of the system doesn't get to control it. This sort of e2e attestation seems really useful for enterprise or public infrastructure. Like, it'd be great to know that the ATMs or transit systems i…
> You argument correctly points out that attestation tech can be used to restrict software freedom, but it also assumes that this company is actively pursuing those use cases. I don't think that is a given. Once it's out there and normalized, the individual engineers don't get to control how it is used. They never do.
Lennart Poettering, Christian Brauner founded a new company
651–660 of 770 posts
Re: Lennart Poettering, Christian Brauner founded a new company
#652The typical HN rage-posting about DRM aside, there's no reason that remote attestation can't be used in the opposite direction: to assert that a server is running only the exact code stack it claims to be, avoiding backdoors. This can even be used with fully open-source software, creating an opportunity for OSS cloud-hosted services which can guarantee that the OSS and the build running on the server match. This is a…
There is: corporate will fund this project and enforce its usage for their users not for the sake of the users and not for the sake of doing any good.
What it will be used for is to bring you a walled garden into Linux and then slowly incentivize all software vendors to only support that variety of Linux.
LP has a vast, vast experience in locking down users' freedom and locking down Linux.
Re: Lennart Poettering, Christian Brauner founded a new company
#653First thing that comes to mind is anti cheat software. Would that be something solved if these objectives are achieved?
Community ran servers with community administration who actually cared about showing up and removing bad actors and cheaters.
Plenty of communities are still demonstrating this exact fact today.
Companies could 100% recreate this solution with fully hosted servers, with an actually staffed moderation department, but that slightly reduces profit margins so fuck you. Keep in mind community servers ran on donations most of the time. That's the level of profit they would lose.
Companies completely removed community servers as an option instead, because allowing you to run your own servers means you could possibly play the game with skins you haven't paid for!!! Oh no!!! Getting enjoyment without paying for it!!!
All software attempts at anti-cheat are impossible. Even fully attested consoles have had cheats and other ways of getting an advantage that you shouldn't have.
Cheating isn't defined by software. Cheating is a social problem that can only be solved socially. The status quo 20 years ago was better.
Re: Lennart Poettering, Christian Brauner founded a new company
#654Earlier quoted context omitted.
As someone who's lost many hours troubleshooting systemd failures, I would like an answer to this question, too.
You won't believe how many hours we have lost troubleshooting SysV init and Upstart issues. systemd is so much better in every way, reliable parallel init with dependencies, proper handling of double forking, much easier to secure services ( systemd-analyze security ), proper timer handling (yay, no more cron), proper temporary file/directory handling, centralized logs, etc. It improves on about every level compared…
You realize that quite a few senior and experienced developers and devops engineers do not share this view, right?
Re: Lennart Poettering, Christian Brauner founded a new company
#655Hi Chris, One of the most grating pain points of the early versions of systemd was a general lack of humility, some would say rank arrogance, displayed by the project lead and his orbiters. Today systemd is in a state of "not great, not terrible" but it was (and in some circles still is) notorious for breaking peoples' linux installs, their workflows, and generally just causing a lot of headaches. The systemd project…
Of course it will not be answered. And that's exactly an answer to your question.
Re: Lennart Poettering, Christian Brauner founded a new company
#656Really excited to a company investing into immutable and cryptographically verifiable systems. Two questions really: 1. How will the company make money? (You have probably been asked that a million times :).) 2. Similar to the sibling: what are the first bits that you are going to work on. At any rate, super cool and very nice that you are based in EU/Germany/Berlin!
1. We are confident we have a very robust path to revenue. 2. Given the team, it should be quite obvious there will be a Linux-based OS involved. Our aims are global but we certainly look forward to playing an important role in the European tech landscape.
I have no more information about your product that you have shared but I'm already scared and extremely pessimistic given the team and the ambition.
Re: Lennart Poettering, Christian Brauner founded a new company
#657Earlier quoted context omitted.
> Where/who have you received funding from I don't think you will ever get a response to that
It's pretty normal to say who leads your investing rounds is it not? I'm not asking for a client list, to be clear.
Re: Lennart Poettering, Christian Brauner founded a new company
#658Earlier quoted context omitted.
That seems like a fair point about the documentation! As far as I can see, you're right.
So that's why I find his statements disturbing. If he really don't want targets to deliver failed/success guarantees, then they've massively miscommunicated in their documentation. That in my book is a huge deal. In either case the issue should in no circumstance be casually dismissed as not-a-bug without further action.
I'm sure the project would accept a documentation patch to amend this discrepancy. At the end of the day (despite what some people on the internet might like to allege), systemd is a free software project that, despite having (more or less) a BIFL, is ultimately a relatively bazaar-like project.
Though since these targets and unit properties are very core to systemd-the-service manager, I do think that this is a bigger documentation oversight than most.
Re: Lennart Poettering, Christian Brauner founded a new company
#659Well I was wondering when the war on general computing and computer ownership would be carried into the heart of the open source ecosystems. Sure, there are sensible things that could be done with this. But given the background of the people involved, the fact that this is yet another clear profit-first gathering makes me incredibly pessimistic. This pessimism is made worse by reading the answers of the founders here…
> [T]he war on general computing and computer ownership [...] It is exhausting to see the hatred some have for people just owning their hardware. The integrity of a system being verified/verifiable doesn't imply that the owner of the system doesn't get to control it. This sort of e2e attestation seems really useful for enterprise or public infrastructure. Like, it'd be great to know that the ATMs or transit systems i…
The problem is that there are powerful corporate and government interests who would love nothing more than to prevent users from controlling the keys for their own computers, and they can make their dream come true simply by passing a law.
It may be the case that certain users want to ensure that their computers are only running their code. But the same technologies can also used to ensure that their computers are only running someone else's code, locking users out from their own devices.
Re: Lennart Poettering, Christian Brauner founded a new company
#660Earlier quoted context omitted.
How does it solve MITM? You type your hardware token in and then an attacker uses it to send money out of your account. >What exactly is the concern here? Stealer malware. Or even RATs where attackers get notified when you open a sensitive app and they can take over after you have authenticated.
Could you please spell out the specifics of this scenario? MitM via an evil (ie incorrect) domain name is prevented because U2F (and now webauthn or CTAP2) are origin bound. RATs? On stock android? How does that work? And how are the things you describe not also threats for online banking via a browser? It's certainly not how the vast majority of attacks take place in the wild. Can you provide any examples of such an…
This is assuming the user's device is not compromised.
>How does that work?
Priviledge escalation on an old OS version allows an attacker to get root access. Then with that they can bypass any sandboxing. Or they could get access to some android permission intended for system apps that they should not have access to and use that to do malicous things.
I don't closely follow malware outbreaks for android so I can't point to specific examples, but malware does exist.