Live data from Hacker News

Lennart Poettering, Christian Brauner founded a new company

amutable.com

761–770 of 770 posts

Re: Lennart Poettering, Christian Brauner founded a new company

#761

Well I was wondering when the war on general computing and computer ownership would be carried into the heart of the open source ecosystems. Sure, there are sensible things that could be done with this. But given the background of the people involved, the fact that this is yet another clear profit-first gathering makes me incredibly pessimistic. This pessimism is made worse by reading the answers of the founders here…

I do sort of wonder if there’s room in my life for a small attested device. Like, I could actually see a little room for my bank to say “we don’t know what other programs are running on your device so we can’t actually take full responsibility for transactions that take place originated from your device,” and if I look at it from the bank’s point of view that doesn’t seem unreasonable. Of course, we’ll see if anybody…

> if the bank or Netflix want to send me a locked down terminal to act as a portal to their services, I guess I would be fine with using it to access (just) their services

They would only do it to assert more control over you and in Netflix's case, force more ads on you.

It is why I never use any company's apps.

If they make it a requirement, I will just close my account.

Re: Lennart Poettering, Christian Brauner founded a new company

#762
post #717

Earlier quoted context omitted.

I still need to use alsamixer to unmute my headphones after accidentally unplugging them and plugging them in again fails to do so. That's with PipeWire - never had that problem with just ALSA.

Eh, I had to do that with pulseaudio too, but constantly, across all distros and headphones. Pipewire is shonky, I have to restart now and then on my steam deck (I'm using it as a desktop), but it's still much better than pulseaudio. Even ALSA was better than pulseaudio lol

For most of the (sadly not shorter) life of PulseAudio, ALSA was more reliable, but at some point, Firefox got a new audio backend that straight up dropped support for ALSA, and a few games started crashing with backtraces indicating audio trouble when not run with PulseAudio. I've had to deal with PulseAudio's dropouts under load, latencies and lockups for 2-3 years before PipeWire became a viable replacement.

Re: Lennart Poettering, Christian Brauner founded a new company

#763
post #51

Earlier quoted context omitted.

I'm Aleksa, one of the founding engineers. We will share more about this in the coming months but this is not the direction nor intention of what we are working on. The models we have in mind for attestation are very much based on users having full control of their keys. This is not just a matter of user freedom, in practice being able to do this is far more preferable for enterprises with strict security controls. I…

that’s great that you’ll let users have their own certificates and all, but the way this will be used is by corporations to lock us out into approved Linux distributions. Linux will be effectively owned by RedHat and Microsoft, the signing authority. it will be railroaded through in the same way that systemD was railroaded onto us.

> but the way this will be used is by corporations to lock us out into approved Linux distributions. Linux will be effectively owned by RedHat and Microsoft, the signing authority.

This is the intent of the Poettering and Brauner.

Re: Lennart Poettering, Christian Brauner founded a new company

#764

Earlier quoted context omitted.

Can you (or someone) please tell what’s the point, for a regular GNU/Linux user, of having this thing you folks are working on? I can understand corporate use case - the person with access to the machine is not its owner, and corporation may want to ensure their property works the way they expect it to be. Not something I care about, personally. But when it’s a person using their own property, I don’t quite get the p…

The value is being able to easily and robustly verify that my device hasn't been compromised. Binding disk encryption keys to the TPM such that I don't need to enter a password but an adversary still can't get at the contents without a zero day. Of course you can already do the above with secure boot coupled with a CPU that implements an fTPM. So I can't speak to the value of this project specifically, only build and…

> The value is being able to easily and robustly verify that my device hasn't been compromised.

That is impossible.

"secure" devices get silently tampered with everyday.

You can never guarantee that.

Re: Lennart Poettering, Christian Brauner founded a new company

#765

Earlier quoted context omitted.

You could tell this sort of insinuation to anyone. Including you. Argument should be technical.

Insinuation? As a sw dev they don't have any agency over whether or by whom they get acquired. Their decision will be whether to leave if it's changing to the worse, and that's very much understandable (and arguably the ethical thing to do).

Do you mean like IBM takeover of RedHat?

Re: Lennart Poettering, Christian Brauner founded a new company

#766

Earlier quoted context omitted.

You could tell this sort of insinuation to anyone. Including you. Argument should be technical.

That's a perfectly valid objection to this proposal. You only have to look at what happened to Hashicorp to see the risk.

How can anyone promise that? Will you promise to your current employer that you will never leave the job?

Re: Lennart Poettering, Christian Brauner founded a new company

#767

Earlier quoted context omitted.

So do we just give up because it's too hard?

It's not a matter of being hard. It's like trying to prevent theft by forcing everyone to wear a specific brand of shoes. The fact that the shoe company insists that it's useful is not evidence that it is. It's not that you can't solve the problem, it's that you can't solve the problem using that mechanism . Attestation is useless for this. The thing that would actually work for this is to have an open standard suppo…

From what I can take from your reply I suspect you might not understand what attestation is for.

Yes you can use a chip that the bank trusts (that's your card), however the bank wants to trust that the hardware you use to read that chip is not compromised and does not try to do things on the behalf of the user that the user didn't authorize. A non trusted device can operate in a different way than the user demands of it, and the user might never know.

That's the use case that hardware attestation can prevent. Or so the theory says...

Re: Lennart Poettering, Christian Brauner founded a new company

#768

Earlier quoted context omitted.

That's a perfectly valid objection to this proposal. You only have to look at what happened to Hashicorp to see the risk.

How can anyone promise that? Will you promise to your current employer that you will never leave the job?

No, but I can promise to my current employer that me leaving my job won’t be a critical problem.

It’s less of an issue in the case of a normal job than in an open source project where often the commitment of particular founding individuals to the long-term future of the project is a big part of people’s decision to use or not use that tech in their solutions. Here, given that “Trusted computing” can potentially lock you out of devices you have bought, it’s important for people to be able to judge the risk of getting “legal ransomware”d if the trusted computing base ends up depending on a proprietary component that they can’t back out of.

That said, there is absolutely zero chance that I use this (systemd is already enough Poettering software for me in this lifetime) so I’m not personally affected either way.

Re: Lennart Poettering, Christian Brauner founded a new company

#769

Earlier quoted context omitted.

How can anyone promise that? Will you promise to your current employer that you will never leave the job?

No, but I can promise to my current employer that me leaving my job won’t be a critical problem. It’s less of an issue in the case of a normal job than in an open source project where often the commitment of particular founding individuals to the long-term future of the project is a big part of people’s decision to use or not use that tech in their solutions. Here, given that “Trusted computing” can potentially lock…

Again lots of doomsayers like you said it when systemd was introduced. Nothing happened. Same with RedHat IBM takeover.

Re: Lennart Poettering, Christian Brauner founded a new company

#770

Earlier quoted context omitted.

All this theatre is turning out to be nothing more than giving up the agency we have today (nice things), for a risk averse kneejerk runaround with glaring ulterior motives...just like the scan your face+id push for services.

Would YOU be willing to use a bank that refused to use TLS? I didn't think so. How is you refusing to accept remote attestation and the bank refusing to connect to you any different?

Because it's not about security, and bank doesn't own my device. If it was, I should be able to supply the bank my own attestation keys.
Post reply on HN