Live data from Hacker News

Brave New Trusted Boot World

0pointer.net

81–90 of 178 posts

Re: Brave New Trusted Boot World

#81
post #6
post #2

>System ready for easy remote attestation, to prove validity of booted OS, configuration and local identity >“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated. In what world is this a…

Humanity has done a great step forward in the last 50 years or so, usually you can trust the police and governments everywhere on the planet today to always do the right thing. So why this irrational fear and this anti-state ideology? Don´t you love our modern leaders?

> usually you can trust the police and governments everywhere on the planet today to always do the right thing

You jest, but a weaker form of "you can usually trust the police and governments today to do the right thing" is very much true for regular citizens in civilized countries.

The two problem cases are 1) people working to keep those governments in check, which is a necessary function for their operation but one that, by definition, said governments don't like, and 2) the private sector. The private sector can, and will, abuse everything it can get its hands on, to the extent permitted by the most strict reading of the letter of the law.

Re: Brave New Trusted Boot World

#82

As somone who never really viewed systemd as a problem I'm starting to think the systemd "haters" were actually right, at least somewhat... Viewing Poettering as some kind malicious entity undermining projects sounds like a conspiracy theory. But now with him working for Microsoft his actions do look like a lot like the "embrace, extend, and extinguish" pattern to me. Yes, yes "Microsoft And now I am supposed to chee…

Never attribute to malice what could be explained by... well Poettering isn't stupid really, he's clearly very talented and intelligent, but I don't think he's doing it with intent more than he doesn't really think ahead to what the system he's creating is turning into. Again, I'd say most of the developer world has this issue, just see the post a few days ago from the guy who volunteers to help elderly folks with th…

Its Foresight. Poettering is a able person, but lacks any foresight on what world he is creating.

Re: Brave New Trusted Boot World

#83

Earlier quoted context omitted.

That's the entire point. Your bank doesn't want you to run their software on your potentially vulnerable hardware.

That's the entire point of conflict: to me, that's an overreach by the bank, who's now dictating things out of scope of the relationship between us. The traditional boundary is one drawn by device ownership: my device, my rules; their device, their rules. I.e. my phone can do whatever, their servers can refuse working with me. Remote attestation is at best a way for simplifying their own service, at a big cost to use…

> The traditional boundary is one drawn by device ownership: my device, my rules; their device, their rules.

Your device your rules seems to cover this, too: they’re saying they don’t want to do business under other rules – the app is just showing the UI for that policy client side.

It’s frustrating but that seems not unreasonable given the massive ratio of people being compromised versus intentionally customizing the OS. I miss the free-for-all of the 90s in some ways but statistically zero of the non-IT people I know wouldn’t hand root on their phone over to some guy in another country based on a prompt on a webpage.

Re: Brave New Trusted Boot World

#84
Now that's the most ominous title I've read all year, and it's a piece in favor of it? Maybe I've just read too many dystopian novels, but come on.

I'm all in favor of secure boot as long as I can enroll my own keys, but remote attestation gets scary quickly.

Re: Brave New Trusted Boot World

#85
post #75

Earlier quoted context omitted.

This is unfair. MS keeps making it harder and harder to run anything that is not MS-signed (TM) on Secure Boot hardware; any distro that does not bow to the whims of MS is thus likely to be relegated to obscurity or die due to lack of users capable of installing it.

I keep hearing that Microsoft is making things "harder", but I've yet to see any evidence that this is true. All I can see is that Microsoft mandate that laptop hardware sold with Windows installed have secure boot capability and that the MS-signing keys are shipped in the TPM. This has been true for, what, over 10 years? How are they making things harder?

There are quite a few instances[1] where adding your own signing keys bricks the device.

[1] https://wiki.archlinux.org/title/Unified_Extensible_Firmware...

Re: Brave New Trusted Boot World

#86
post #56
post #39

Earlier quoted context omitted.

No-one's making you use it. Choose a distro that doesn't package it - there's plenty to choose from.

This number diminishes every passing year, with only debian being a bastion of sanity on the "user friendly" side of the distro spectrum.

Debian only supports systemd though? No sure what you mean by bastion in the context of systemd. Devuan is the Debian non-systemd fork.

Re: Brave New Trusted Boot World

#87
post #75

Earlier quoted context omitted.

This is unfair. MS keeps making it harder and harder to run anything that is not MS-signed (TM) on Secure Boot hardware; any distro that does not bow to the whims of MS is thus likely to be relegated to obscurity or die due to lack of users capable of installing it.

I keep hearing that Microsoft is making things "harder", but I've yet to see any evidence that this is true. All I can see is that Microsoft mandate that laptop hardware sold with Windows installed have secure boot capability and that the MS-signing keys are shipped in the TPM. This has been true for, what, over 10 years? How are they making things harder?

A recent example https://mjg59.dreamwidth.org/59931.html , discussed here at HN https://news.ycombinator.com/item?id=32023868 , in which ironically MS is making it harder to run stuff which _is_ MS-signed (the current version of Windows being exempt, of course).

Re: Brave New Trusted Boot World

#88

As somone who never really viewed systemd as a problem I'm starting to think the systemd "haters" were actually right, at least somewhat... Viewing Poettering as some kind malicious entity undermining projects sounds like a conspiracy theory. But now with him working for Microsoft his actions do look like a lot like the "embrace, extend, and extinguish" pattern to me. Yes, yes "Microsoft And now I am supposed to chee…

Never attribute to malice what could be explained by... well Poettering isn't stupid really, he's clearly very talented and intelligent, but I don't think he's doing it with intent more than he doesn't really think ahead to what the system he's creating is turning into. Again, I'd say most of the developer world has this issue, just see the post a few days ago from the guy who volunteers to help elderly folks with th…

If I was Lennart I'd gladly go along with whatever evil scheme MS has in mind to exact my revenge on all the neckbeards that have attacked him over the years.

Re: Brave New Trusted Boot World

#89
post #35

I'm OK with making sure the software I'm running is the software I thought I was running. But because trusted boot runs so deep, and is intentionally hard to get around, it's vital that the implementation is trustworthy. I don't trust Poetteringware. Poettering's team has a record of foisting technology on users, resulting in the need for e.g. the Devuan fork. I wish this work were being done by just about any other…

Going back to the init.d clusterfuck is insane.

I was thinking this in a general sense, but I recently tried a distro with openrc and it was quite nice. Maybe things have changed.

Re: Brave New Trusted Boot World

#90
post #83

Earlier quoted context omitted.

That's the entire point of conflict: to me, that's an overreach by the bank, who's now dictating things out of scope of the relationship between us. The traditional boundary is one drawn by device ownership: my device, my rules; their device, their rules. I.e. my phone can do whatever, their servers can refuse working with me. Remote attestation is at best a way for simplifying their own service, at a big cost to use…

> The traditional boundary is one drawn by device ownership: my device, my rules; their device, their rules. Your device your rules seems to cover this, too: they’re saying they don’t want to do business under other rules – the app is just showing the UI for that policy client side. It’s frustrating but that seems not unreasonable given the massive ratio of people being compromised versus intentionally customizing th…

> Your device your rules seems to cover this, too: they’re saying they don’t want to do business under other rules – the app is just showing the UI for that policy client side.

I guess I see two problems here:

1) They shouldn't be allowed to make that policy in the first place. Their policy is effectively dictating what devices I can own and what can I do with them, which is unreasonable when the devices in question are general-purpose computers.

2) My device is being used against me and against my wishes here; I'm not sure who's more to blame here - the bank for taking advantage of the API, Google for providing it, or the phone vendor for implementing it and locking me out of it, or Google again for effectively forcing the phone vendor to lock me out of it.

> I miss the free-for-all of the 90s in some ways but statistically zero of the non-IT people I know wouldn’t hand root on their phone over to some guy in another country based on a prompt on a webpage.

There must be some other way of handling it. We wouldn't have the Fisher-Price tech of 2020s without the free-for-all 90s! The ability for technically proficient users to do whatever the hell they want with their own general-purpose computers is fundamental to developing new technologies, products and services, and better alternatives to existing ones. Between Fisher-Price consumer tech and locked down corporate tech (because security!), it looks like we're heading for an era where a general-purpose computer will be something available only to few certified employees in corporate-sponsored labs.

Post reply on HN