5 ms·
Joanna's brilliant, and this Golem project is fascinating. The idea of a secure remote compute arrangement is sort of a natural extension from Qubes, and this
by wanderfowl 8y ago
Joanna's brilliant, and this Golem project is fascinating. The idea of a secure remote compute arrangement is sort of a natural extension from Qubes, and this is a pretty unique approach. May she (and Qubes, and Golem) find great success.
- wanderfowl 8y agoReading the Golem website, I'm no longer sure that I 'get it'. Is this just a decentralized AWS or supercomputing service which is payable using $ThisWeeksHotCryptocurrency? Her description made it sound less like a marketplace for spare cycles and more like a thin-client sort of thing.
- hackermailman 8y agoIt's a Graphene SGX fork running docker containers so far.
- deleted 8y ago[deleted]
- jacoblambda 8y agoIn the end it is supposed to be a decentralised AWS/cloud computing service with the benefits that computation is more or less private (limited to no snooping) and (the actually important bit) with market driven pricing that seems to be driving the cost below that of AWS. Sia and a number of other projects are trying to address hot and cold storage while Golem and company are addressing the compute. With some clever architecture design, these decentralised systems could be combined to make a decentralised remote server.
- forapurpose 8y ago> a secure remote compute arrangement is sort of a natural extension from Qubes I see what you mean, but on the other hand it's a threat to the endpoint security she's worked so hard on. If Intel offered a solution that allowed remote users to run code on your machine, no matter how secure they claimed it to be the response here would rightfully be 'what could go wrong?' Can it be made secure enough? (I'm aware that Intel already offers such things, including via SGX which others in this discussion say is utilized by Golem.)
- wanderfowl 8y agoSure, but at the same time, a big part of Qubes involved creating very secure jails for processes, which they could not escape. So, 'keeping untrusted stuff in its box' is sort of her expertise, and if anybody's going to do that right, it's probably her. Chances are, the NSA won't be renting out Top Secret machines for Golem, but some rando with a multi-thousand dollar gaming rig she's just using to browse HN on may well view the tradeoff differently.
- wolfgke 8y ago> some rando with a multi-thousand dollar gaming rig she's just using to browse HN on may well view the tradeoff differently. I don't think so since you will immediately hear the difference in terms of fan noise. :-)
- glitch003 8y agoSeems like an acceptable tradeoff, like if it's cold in her room and she wants to get paid to heat it
- effie 8y agoYou have a very naive view of the quality of isolation Qubes OS can provide. It is currently basically sanely configured Xen domains with some python helper scripts. There is nothing in the way Qubes OS does isolation that would suggest some exceptional expertise in process isolation. That kind of expertise is more appropriately sought in projects like sel4, Genode, etc.
- Kototama 8y agoAnother "natural" direction would have been to work on the security of smartphones.
- wanderfowl 8y agoConsidering the amount of pain going into fighting the million drivers and black-box chips in a commodity X86 box where you can run user code as root, I can't imagine a smartphone would provide anything but suffering for a Qubes-style security project. Unless, of course, $OEM was directly on board with the research or work, and willing to modify the software and hardware as needed.
- seba_dos1 8y agoLibrem 5 from Purism, PinePhone from Pine64, Necuno Mobile from Necuno... even the DragonBox Pyra if you really stretch it. In 2018, it starts to seem doable again :P
- jazzyjackson 8y agoThat would probably turn into a silicon fabbing endeavor since almost everything that can talk to a cell network is proprietary
- shmerl 8y agoSo someone should make a project to open this up?
- crankylinuxuser 8y agoThat's not entirely true these days. I have a ADALM-PLUTO sdr that can do duplex from 70MHz-6GHz. Only 5mW (7dBm) Tx. But there is a Gnu Radio gr-gsm and gr-lte plugins to make your own client (cell phone) and server (tower). There was also a nice talk at DerbyCon that went further in what you need to do to handle tower ops.