Live data from Hacker News

Lennart Poettering, Christian Brauner founded a new company

amutable.com

701–710 of 770 posts

Re: Lennart Poettering, Christian Brauner founded a new company

#701
post #70

Earlier quoted context omitted.

Thanks Daan for your contributions to systemd. If you were not a systemd maintainer and have started this project/company independently targeting systemd, you would have to go through the same process as everyone and I would have expected the systemd maintainers to, look at it objectively and review with healthy skepticism before accepting it. But we cannot rely on that basic checks and balances anymore and that's th…

Systemd upstream has reviewers and maintainers from a bunch of different companies, and some independent: Red Hat, Meta, Microsoft, etc. This isn't changing, we'll continue to work through consensus of maintainers regardless of which company we work at.

> companies

That's the keyword.

Companies. Not people.

Re: Lennart Poettering, Christian Brauner founded a new company

#702

Earlier quoted context omitted.

I don't think this is right. Usually, the entity that owns secure boot keys is a large tech corporation which paid to install their keys on all new computers.

You can enroll your own and LP goal is basically based on the assumption that you can enroll your own

Until you cannot.

Re: Lennart Poettering, Christian Brauner founded a new company

#703

Earlier quoted context omitted.

Unless that malware is able to activate the secure boot feature on a system where it is not enabled, in which case it permanently prevents me from removing the malware.

Then you reset the firmware and re-enroll your SB keys or disable it completely.

> re-enroll your SB keys

This is possible only temporarily.

Re: Lennart Poettering, Christian Brauner founded a new company

#704
post #40

The immediate concern seeing this is will the maintainer of systemd use their position to push this on everyone through it like every other extended feature of systemd? Whatever it is, I hope it doesn't go the usual path of a minimal support, optional support and then being virtually mandatory by means of tight coupling with other subsystems.

> will the maintainer of systemd use their position to push this on everyone

Can you imaging the creator of systemd not to?

Re: Lennart Poettering, Christian Brauner founded a new company

#705
post #182

I think https://0pointer.net/blog/authenticated-boot-and-disk-encryp... is a much better explanation of the motivation behind this straight from the horse's mouth. It does a really good job of motivating the need for this in a way that explains why you as the end user would desire such features.

The motivation is nice. The idea has merit.

It's the people behind this project who scare me.

Re: Lennart Poettering, Christian Brauner founded a new company

#706

So much negativity in this thread. I actually think this could be useful, because tamper-proof computer systems are useful to prevent evil maid attacks. Especially in the age of Pegasus and other spyware, we should also take physical attack vectors into account. I can relate to people being rather hostile to the idea of boot verification, because this is a process that is really low level and also something that we a…

> I actually think this could be useful

Yeah it could be. Could. But it also could be used for limiting freedoms with general purpose computing. Guess what is it going to be?

> hostile to the idea of boot verification, because this is a process that is really low level

Not because of that.

Because it's only me who gets to decide what runs on my computer, not someone else. I don't need LP's permission to run binaries.

Re: Lennart Poettering, Christian Brauner founded a new company

#708

Looking forward to never using any of this, quite frankly; and hoping it remains optional for the kernel. If there’s a path to profitability, great for them, and for me too; because it means it won’t be available at no charge.

No one wants this for their computer.

These kind of technologies are forced on users.

Re: Lennart Poettering, Christian Brauner founded a new company

#709
post #18

Earlier quoted context omitted.

The events includes a conference title "Remote Attestation of Imutable Operating Systems built on systemd", which is a bit of a clue.

I'm sure this company is more focused on the enterprise angle, but I wonder if the buildout of support for remote attestation could eventually resolve the Linux gaming vs. anti-cheat stalemate. At least for those willing to use a "blessed" kernel provided by Valve or whoever.

> resolve the Linux gaming vs. anti-cheat stalemate

It will.

Then just a bit later no movies for you unless you are running a blessed distro. Then Chrome will start reporting to websites that you are this weird guy with a dangerous unlocked distro, so no banking for you. Maybe no government services as well because obviously you are a hacker. Why would you run an unlocked linux if you were not?

Re: Lennart Poettering, Christian Brauner founded a new company

#710
post #294

Earlier quoted context omitted.

This is basically propaganda for the war on general purpose computing. My user data is less safe on a Windows device, because Microsoft has full access to that device and they are extremely untrustworthy. On my Linux device, I choose the software to install.

What are you talking about? This has nothing to do with general purpose computing and everything to do with allowing you to authenticate the parts of the Linux boot process that must by necessity be left unencrypted in order to actually boot your computer. This is putting SecureBoot and the TPM to work for your benefit. It's not propaganda in any sense, it's recognizing that Linux is behind the state of the art compa…

> allowing you to authenticate the parts of the Linux boot

No, not you. Someone else for you. And that's the scary part.

Post reply on HN