Live data from Hacker News

Lennart Poettering, Christian Brauner founded a new company

amutable.com

741–750 of 770 posts

Re: Lennart Poettering, Christian Brauner founded a new company

#741

Earlier quoted context omitted.

> [T]he war on general computing and computer ownership [...] It is exhausting to see the hatred some have for people just owning their hardware. The integrity of a system being verified/verifiable doesn't imply that the owner of the system doesn't get to control it. This sort of e2e attestation seems really useful for enterprise or public infrastructure. Like, it'd be great to know that the ATMs or transit systems i…

You want PCIe-6? Cool well that only runs on Asus G-series with AI, and is locked to attested devices because the performance is so high that bad code can literally destroy it. So for safety, we only run trusted drivers and because they must be signed, you have to use Redhat Premium at a monthly cost of $129. But you get automatic updates.

Do you want the control systems of the subway to get modified by a malicious actor? What about damn releases? Heat pumps in apartment buildings? Robotaxis? Payroll systems? Banks?

Amutability is a huge security feature, with tons of real world applications for good.

The fact that mega corps can abuse consumers is a separate issue. We should solve that with regulation. Don't forsake all the good that this tech can do just because Asus or Google want to infringe on your software freedoms. Frankly, these mega corps are going to infringe on your rights regardlessly, whether or not Amutable exists as a business.

Don't throw the baby out with the bath water.

Re: Lennart Poettering, Christian Brauner founded a new company

#742
post #738

Earlier quoted context omitted.

> it will be used for movies, government services, banks I really, really don't think these entities care enough about desktop Linux. I'd be way more worried about some kind of Windows web-based attestation appearing. If that happens I really do think there's a bit of an alarm to sound, because this will make using desktop Linux inconvenient in the way attestation has made using alternate Android ROMs inconvenient. >…

Android strict attestation is popular because fraudulent cloned banking apps are a rampant problem for banks, not because they're trying to "stick it" to 200 GrapheneOS users. Where I live in Europe, Fairphones are becoming fairly popular (as in, I encounter non-tech people using Fairphones). A subset of those users run /e/OS (anti-Google/big tech sentiment is growing pretty strong). This is increasingly becoming a r…

> If all they cared for was security, they would have worked with other Android-based operating system vendors that support bootloader locking to come with an industry-wide standard.

Google actually "gave" customers the choice here, although I agree with you that it's crappy and there was almost surely some monopolistic intent -

There _is_ a standard implementation, the Hardware Attestation API. Unfortunately it is annoying to use in a practical way; it requires a fair amount of PKI-wrangling (although there's a Google library for it) and more importantly to allow non-Google trust chains but still enforce boot security, app developers need all of the verifiedBootKey hashes for the non-Google trust chains they want to trust. This makes sense, but unfortunately becomes a maintenance problem and turns app developers off of this.

So, app developers choose the Play Integrity API instead because it's easy, even though they get the side effect that they verify that the device is a licensed Google Play device rather than just a "clean" Android device.

All this is to say that if something like /e/OS were to actually take off, app developers could upgrade their apps to support attestation with the Hardware Attestation API with some extra effort - Google aren't really preventing them and the feature is there.

Anyway, going all the way back to the original story again, I still can't buy into the hand-wringing. A verified, attestable Linux on the server (or for stuff like forward deployed devices) seems quite cool and useful to me, and while I respect the issues with client attestation and the negative effect it can have on hardware ownership, I both don't see it as a practical outcome from this company and don't see it as a practical threat on the desktop at this time.

Re: Lennart Poettering, Christian Brauner founded a new company

#743
post #294

Earlier quoted context omitted.

What are you talking about? This has nothing to do with general purpose computing and everything to do with allowing you to authenticate the parts of the Linux boot process that must by necessity be left unencrypted in order to actually boot your computer. This is putting SecureBoot and the TPM to work for your benefit. It's not propaganda in any sense, it's recognizing that Linux is behind the state of the art compa…

> allowing you to authenticate the parts of the Linux boot No, not you. Someone else for you. And that's the scary part.

Yes you. The parts being expanded upon happen after the shim is authenticated by SecureBoot and are fully in your control. The scary part has already happened, Linux distros support SecureBoot right now and have for a while. Right now the current state of the Linux boot process is all the downsides (in your view) of SecureBoot with none of the upsides because very little is authenticated after that.

Re: Lennart Poettering, Christian Brauner founded a new company

#744
post #294

Earlier quoted context omitted.

What are you talking about? This has nothing to do with general purpose computing and everything to do with allowing you to authenticate the parts of the Linux boot process that must by necessity be left unencrypted in order to actually boot your computer. This is putting SecureBoot and the TPM to work for your benefit. It's not propaganda in any sense, it's recognizing that Linux is behind the state of the art compa…

> we should improve the Linux boot process to be a tight security-wise as the Windows I hope this never happens. I really want my data secure and I do have something to hide. So, no Microsoft keys on my computer and only I will decide what kind of software I get to run. Absolutely fuck that.

So to I guess spite Microsoft or something you're going to make your data less secure?

Turning off SecureBoot only means any rando can decide what software runs on your device and install a bootkit. Not authenticating the rest of the boot process as outlined here (what Microsoft calls Trusted Boot) only means that randos can tamper with your OS using the bits that can't be encrypted.

Literally an own-goal in every sense of the word.

Re: Lennart Poettering, Christian Brauner founded a new company

#745

Awful. I hope they fall.

anything that keeps him away from systemd is a good thing. systemd kept him away from pulseaudio and whoever is/was maintaining that after him was doing a good job of fixing it.

The ultimate fix was to throw it out and replace it. Pipewire is a so much better system.

Re: Lennart Poettering, Christian Brauner founded a new company

#746
post #565

Earlier quoted context omitted.

No.

Why not? Being terse does not make one right...

Off the top of my head, because

- You're just moving your trust elsewhere, this time to a private corporation (whoever makes the CPU / TPM / other "trusted" component).

- This doesn't guarantee voter anonymity the way paper ballots do. Considering the analog hole and the complexity of computers, I can think of a billion ways a motivated and resourceful Mallory could to connect someone to their ballot.

Re: Lennart Poettering, Christian Brauner founded a new company

#747

Well I was wondering when the war on general computing and computer ownership would be carried into the heart of the open source ecosystems. Sure, there are sensible things that could be done with this. But given the background of the people involved, the fact that this is yet another clear profit-first gathering makes me incredibly pessimistic. This pessimism is made worse by reading the answers of the founders here…

> [T]he war on general computing and computer ownership [...] It is exhausting to see the hatred some have for people just owning their hardware. The integrity of a system being verified/verifiable doesn't imply that the owner of the system doesn't get to control it. This sort of e2e attestation seems really useful for enterprise or public infrastructure. Like, it'd be great to know that the ATMs or transit systems i…

System integrity also ends at the border of the system. The entire ecosystem of ATM skimmers demonstrates this-- the software and hardware are still 100% sanctioned, they're just hidden beneath a shim in the card slot and a stick-on keypad module.

I generally agree with the concept of "if you want me to use a pre-approved terminal, you supply it." I'd think this opens up a world of better possibilities. Right now, the app-centric bank/media company/whatever has to build apps that are compatible with 82 bazillion different devices, and then deal with the attestation tech support issues. Conversely, if they provide a custom terminal, it might only need to deal with a handful of devices, and they could design it to function optimally for the single use case.

Re: Lennart Poettering, Christian Brauner founded a new company

#748

Earlier quoted context omitted.

You want PCIe-6? Cool well that only runs on Asus G-series with AI, and is locked to attested devices because the performance is so high that bad code can literally destroy it. So for safety, we only run trusted drivers and because they must be signed, you have to use Redhat Premium at a monthly cost of $129. But you get automatic updates.

Do you want the control systems of the subway to get modified by a malicious actor? What about damn releases? Heat pumps in apartment buildings? Robotaxis? Payroll systems? Banks? Amutability is a huge security feature, with tons of real world applications for good. The fact that mega corps can abuse consumers is a separate issue. We should solve that with regulation. Don't forsake all the good that this tech can do…

It seems like we're doing pretty well without the baby. You sell it, you say we need it. Highly credible

Re: Lennart Poettering, Christian Brauner founded a new company

#749
post #744

Earlier quoted context omitted.

> we should improve the Linux boot process to be a tight security-wise as the Windows I hope this never happens. I really want my data secure and I do have something to hide. So, no Microsoft keys on my computer and only I will decide what kind of software I get to run. Absolutely fuck that.

So to I guess spite Microsoft or something you're going to make your data less secure? Turning off SecureBoot only means any rando can decide what software runs on your device and install a bootkit. Not authenticating the rest of the boot process as outlined here (what Microsoft calls Trusted Boot) only means that randos can tamper with your OS using the bits that can't be encrypted. Literally an own-goal in every se…

> Turning off SecureBoot only means any rando can decide what software runs on your device

I see it as exactly the opposite: turning SecureBoot on means someone else can and will decide what software runs on my device.

> spite Microsoft or something you're going to make your data less secure

We all know very well Microsoft's track record with security and with data protection measures and practice. Trusting Microsoft is... irrational, let's put it that way.

Re: Lennart Poettering, Christian Brauner founded a new company

#750
post #743

Earlier quoted context omitted.

> allowing you to authenticate the parts of the Linux boot No, not you. Someone else for you. And that's the scary part.

Yes you. The parts being expanded upon happen after the shim is authenticated by SecureBoot and are fully in your control. The scary part has already happened, Linux distros support SecureBoot right now and have for a while. Right now the current state of the Linux boot process is all the downsides (in your view) of SecureBoot with none of the upsides because very little is authenticated after that.

It's temporary.

In a few years running random code on your computer would be seen a bit unethical.

Post reply on HN