15 ms·
Brave New Trusted Boot World
- no_time 4y ago>System ready for easy remote attestation, to prove validity of booted OS, configuration and local identity >“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated. In what world is this a good thing? This is a one way street to an all seeing police state. I never had a problem with systemd from a technical perspective but looks like Poettering is drinking the TCB kool aid by the barrel.
- pilif 4y agoIf I was responsible for a large enough fleet of machines in my enterprise and I would have to deal with 100s of users of various technical knowledge while at the same time being blamed for the eventual ransomware attack, I would absolutely want to make sure that the only software that gets to run is the one I want running. This (especially) includes the machine's firmware and kernel because that's where malware could effectively hide itself from countermeasures deployed on the machines directly. If I can then also make sure that the various admin interfaces in our network can only be used by machines in a known-good state, I would sleep ever so much better knowing that the various hacks we have seen happening to 1Password, Uber, etc this year cannot happen on my network. I would even say that this is helpful for my users because they will never risk being "the one who let the ransomware in". This isn't about your own private machine. This is about corporation-owned machines in an enterprise network and as we see with nearly biweekly news articles about large-scale ransomware attacks, private data leaks and compromised employee machines, I would argue that the currently employed solutions clearly don't work.
- no_time 4y ago>This isn't about your own private machine. This is about corporation-owned machines in an enterprise network and as we see with nearly biweekly news articles about large-scale ransomware attacks, private data leaks and compromised employee machines, I would argue that the currently employed solutions clearly don't work. The fundamental issue is that you can't have one without the other, and that's bothering me. It's not like only corporate grade laptops come with TPMs now (like they did in the past). Safetynet on my phone is the same thing and it's very much "about my own private machine". Seeing the reactions and the lack thereof about these developments makes me think this will end terribly.
- pilif 4y ago> you can't have one without the other, AFAIK, secure boot can be disabled, both in the BIOS and in the Kernel. In some machines that's not be the case due to contracts with Microsoft, but those already can't run Linux in the first place, so you probably won't buy them for the purpose of running Linux. The suggestions in the original post do not change anything about this.
- no_time 4y agoI am mainly worried about remote attestation encroaching on territory which was traditionally under the user's control. And once this tech reaches critical mass, sure you can disable it however that also means turning your machine into a glorified paperweight that can't access anything arbitrary websites and software.
- kevincox 4y agoYou see this on Android, my banking app requires that it is running an OS approved by a big vendor. Their website, especially the mobile version, is getting more and more tedious to use. I want to be able to access all services with whatever client I please. Not be required to run approved software and hardware that puts them in control.
- growse 4y agoIt sounds like you're demanding to use someone's service on your own terms. I'm not sure why it's obvious that the service provider is under any obligation to entertain your desires. So.... vote with your feet and choose a bank that shares your values more closely?
- kevincox 4y agoYou have a point that the problem isn't the technology but the policy. However the fact is that most banks are moving in this direction so it leaves a consumer little choice.
- deleted 4y ago[deleted]
- nonrandomstring 4y ago> If I was responsible for ... the only software that gets to run is the one I want running. Not wishing to pick on you personally, but the above paragraph is wonderful example of the sort of logic going around that bothers me. You trace a faultless journey from responsibility to desiring total control. That's not what responsibility is. You're describing the feeling of culpability within a brutal regime - where Vader simply force-chokes a lieutenant for "failing me once too often". Responsibility involves leadership, which involves not stripping every subordinate of their agency, dignity and humanity. It involves trusting people. Sadly, computers make a "zero trust" ecosystem far too easy now, and that's how they can destroy our society. Good computing is figuring out ways to preserve liberal democratic society while also improving it.
- api 4y agoThe problem isn’t that you can’t trust people. The problem is that people are defenseless in the face of malicious hackers with vastly more expertise and zero day vulnerabilities. It’s not that you can’t trust your employees. It’s that you can’t trust them to defend themselves from being mugged. The forcing function for all this removal of freedom is defense against malicious hackers. The removal of freedom is not the goal so much as a side effect. It works the same way in the real world. We would not need borders or armies or police if everyone were nice.
- nonrandomstring 4y agoSome good points. Lets see what we can do here: > The problem isn’t that you can’t trust people. Good. It's always best to have an optimistic view of our fellows, that's how we build good social structures. > The problem is that people are defenceless in the face of malicious hackers So. Make then not defenceless. We arm them. With education and other tools they need to defend themselves. Digital Self Defence (Or Digital Literacy 2.0 if you want a fluffier title) is the project I am committed to. Defensive tools belong in the hands of users. > with vastly more expertise We can balance the theatre twofold, by giving people more defensive capability, knowledge and rights, and by attacking the knowledge base and knowledge value of malicious actors. We must recognise that many of our own institutions play part of the problem, from vendor malware, and backdoors to security disinformation. Cyber-law needs radical reform to give end-user better security rights, and "surveillance capitalism" needs dragging to the dock. > zero day vulnerabilities. Starting maybe with an all out assault on "zero days", including the companies, agencies and re-sellers of them, using the law. > It’s that you can’t trust them to defend themselves from being mugged. Part of ones job then, is to enable them to defend themselves. You cannot follow your children around for the rest of their lives in case bullies pick on them. You need to teach them fighting skills so they won't be doormats. That's the reality of the digital workplace today. Also, don't give your kids gold Rolex Oyster watches and diamond rings to mooch around scuzzy neighbourhoods with. Limit assets, practice compartmentalisation. Half an ounce of sensible opsec is worth a ton of authoritarian technical non-solutions. > The removal of freedom is not the goal so much as a side effect. The removal of freedom is NEVER an acceptable "side effect" of any security action. Security and freedom are not diamtrics. Otherwise "the terrorists win" and one may as well join the ranks of malicious principles and directly attack our own people (which is the stance many US agencies have taken since 2001 toward baby and bath-water alike) > real world ... borders armies police But this isn't the real world. Its a digital one which is different. The old military model of perimeters and weapons isn't working and smart people in cybersecurity know that. The collateral damage of that broken model is our digital economy and liberal democracy itself (which are intimately linked in the American/Western mind if you believe one jot in things like startups and entrepreneurialism). We'll simply have to do better than handing over the responsibilities of our elected guardians to unelected companies considered by some [1] to be criminally motivated. We still have laws, schools and hopefully enough common sense to avoid that. EDIT: subtracted fulmination. [1] https://en.wikipedia.org/wiki/United_States_v._Microsoft_Corp https://en.wikipedia.org/wiki/United_States_v._Microsoft_Cor.... https://en.wikipedia.org/wiki/Microsoft_litigation https://en.wikipedia.org/wiki/Microsoft_litigation
- POPOSYS 4y agoHumanity has done a great step forward in the last 50 years or so, usually you can trust the police and governments everywhere on the planet today to always do the right thing. So why this irrational fear and this anti-state ideology? Don´t you love our modern leaders?
- no_time 4y agoMy bad, long live our great leaders!
- richardfey 4y agoHas Snowden written anything on this topic? Just wondering
- TeMPOraL 4y ago> usually you can trust the police and governments everywhere on the planet today to always do the right thing You jest, but a weaker form of "you can usually trust the police and governments today to do the right thing" is very much true for regular citizens in civilized countries. The two problem cases are 1) people working to keep those governments in check, which is a necessary function for their operation but one that, by definition, said governments don't like, and 2) the private sector. The private sector can, and will, abuse everything it can get its hands on, to the extent permitted by the most strict reading of the letter of the law.
- RalfWausE 4y agoMy grandfather had a nice saying: "The state is not your friend nor your ally, it is -at best- a adversary with whom you live in an unstable truce"
- mawalu 4y agoThe TPMs are already in our machines because Microsoft requires them and CPU vendors include them in their chips. They aren't used by default and don't hinder us from doing anything. If I'm already trusting ubuntu to ship me an OS why would I have a problem with having them sign it as well. Secureboot is a scary technology but as long as we can disable it and provide our own keys I don't see the problem. And if we lose these abilities than I'm certain it won't be Poettering or systemd to blame
- jnwatson 4y agoMany folks prioritize preventing practical in-the-wild blue pill attacks over preventing the theoretical DRM use case.
- TeMPOraL 4y agoIt's not a "theoretical DRM use case" if you stop thinking in terms of movie piracy for a moment, and consider what's happening with banking apps on mobile platforms. Thanks to remote attestation, the custom ROM scene for Android is pretty much dead now, because there's little point of customizing the OS when it automatically makes important services no longer accessible from the phone.
- jnwatson 4y agoThat's the entire point. Your bank doesn't want you to run their software on your potentially vulnerable hardware.
- TeMPOraL 4y agoThat's the entire point of conflict: to me, that's an overreach by the bank, who's now dictating things out of scope of the relationship between us. The traditional boundary is one drawn by device ownership: my device, my rules; their device, their rules. I.e. my phone can do whatever, their servers can refuse working with me. Remote attestation is at best a way for simplifying their own service, at a big cost to users' freedom. In reality, it's a bit of that, plus mostly making sure the customers are locked into a bank-controlled channel that can be used to upsell more financial products.
- acdha 4y ago> The traditional boundary is one drawn by device ownership: my device, my rules; their device, their rules. Your device your rules seems to cover this, too: they’re saying they don’t want to do business under other rules – the app is just showing the UI for that policy client side. It’s frustrating but that seems not unreasonable given the massive ratio of people being compromised versus intentionally customizing the OS. I miss the free-for-all of the 90s in some ways but statistically zero of the non-IT people I know wouldn’t hand root on their phone over to some guy in another country based on a prompt on a webpage.
- bjt2n3904 4y agoIt's all about who has the power over the keys. 1. If the user can supply private keys that are treated as first class citizens, then yay! 2. If the user can't supply private keys, or the user's private key is treated as a second class citizen, then boo. Given who is driving TPM usage right now (ie: Microsoft), my intuition says situation 2 is far more likely. I'm continually surprised by the number of people who think this is an unreasonable and/or paranoid.
- bitwize 4y agoThis is where computing as a whole is headed because it's the ONLY way to provide defense in depth against cyberattacks. Signed code path from first boot to user space code. Remote attestation because you can NEVER trust the client. Microsoft and especially Apple are already doing this. Linux needs an answer, and "no, it's too user hostile" is NOT a valid answer; it will just make Linux an untenable security risk. It's like I keep saying, the Wild West 90s internet is long gone and nothing will bring it back. This is where things are headed, because the risks of the status quo are too great. Suck it up and get on with your life.
- krzyk 4y ago> This is where computing as a whole is headed because it's the ONLY way to provide defense in depth against cyberattacks. Yeah, sure - in a fantasy dream world. But the real world has a bit more sophisticated cyberattackers that will find a way in. And at the same time normal and powerusers of computers will have to deal with all the total-control-state-class "security" measures. This looks pretty the same as "think of the children" censorship.
- RalfWausE 4y ago>the Wild West 90s internet is long gone and nothing will bring it back. This is where things are headed, because the risks of the status quo are too great. Suck it up and get on with your life. The "Wind West internet" is very much alive, but as it was in the 90s, its hidden and far away from the "normal" users. And regarding the part with the "suck it up and get on with your life" - I always was a "Don Quijote" type personality, i don't think i will change this attitude...
- selfhoster11 4y agoYou don’t need signing, you need a way to make changing a boot path impossible by anyone who is not the user or the OS (or at least, tamper-evident on reboot). Simply storing hashes that are set on first boot (much like SSH does with known host hashes), and allowing the user/OS to reset the hashes, will be sufficient. M1 does this, as far as I know. > Remote attestation because you can NEVER trust the client. IRL, I don’t carry a weapon everywhere I go, because it’s clearly overkill. For this exact reason, overkill measures like remote attestation should not be a thing on general purpose computers.
- deleted 4y ago[deleted]
- stevewatson301 4y agoThere is something ironic about the FOSS projects these days embracing attestation rather than standing up for user rights by vehemently rejecting it.
- pilif 4y agoIf you were responsible for the security of your enterprise network, would you vehemently fight for your user's rights to run the ransomware executable they just get sent over email?
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- bakugo 4y agoThis may come as a shock to you, but computers exist outside of a corporate context.
- pilif 4y agoI'm aware of that and those computers do not need to use any of these features. But if you're a FOSS project, why should you be advocating for security features to not exist if they provide value for a significant part of their user-base?
- fazfq 4y agoWhy is attestation against user rights?
- stevewatson301 4y agoIn addition to replies to my original comment, see [1] and [2] for the perils that attestation poses against user rights. [1] https://www.gnu.org/philosophy/loyal-computers.en.html https://www.gnu.org/philosophy/loyal-computers.en.html [2] https://www.gnu.org/philosophy/right-to-read.en.html https://www.gnu.org/philosophy/right-to-read.en.html
- denton-scratch 4y agoI'm OK with making sure the software I'm running is the software I thought I was running. But because trusted boot runs so deep, and is intentionally hard to get around, it's vital that the implementation is trustworthy. I don't trust Poetteringware. Poettering's team has a record of foisting technology on users, resulting in the need for e.g. the Devuan fork. I wish this work were being done by just about any other team than Poettering's.
- jle17 4y ago> I don't trust Poetteringware. Poettering's team has a record of foisting technology on users, resulting in the need for e.g. the Devuan fork. They have been developing software, that enough people have deemed useful to include it in their distributions. Some have disagreed, and have made other choices. No one was forced to do anything, there have been no "foisting" and the "need" for Devuan is a subjective opinion. There is really no need to transform purely technical arguments into personal attacks. This just discourages participating into free software development.
- hdjjhhvvhga 4y ago> There is really no need to transform purely technical arguments into personal attacks. This just discourages participating into free software development. While I agree with you in general, for some reason this particular developer tends to take decisions that have very extensive consequences and make choice extremely difficult.
- kevincox 4y agoA developer that has been able to make tough choices and drive them well enough to get mass adoption? He definitely isn't perfect but this sounds like quite the feat in Open Source.
- hdjjhhvvhga 4y agoThere is a huge difference between a developer who creates a superior project that everybody loves to use so it gets mass adoption and one who makes a product that gets pushed by their employer on everyone whether they want it or not. I don't want to get into details as the subject has been beaten to death but as for Systemd* there was the case of integration with graphical login that made choice difficult. Had the author been more sensitive to this issue and cooperated a bit without being stubborn we wouldn't have had Devuan and all that mess. This is exactly NOT the way to do things in open source. *PulseAudio was simply broken but it's not the fault of the author distros picked up aplha-quality software
- peter_d_sherman 4y agohttps://www.joelonsoftware.com/2002/11/11/the-law-of-leaky-abstractions/ https://www.joelonsoftware.com/2002/11/11/the-law-of-leaky-a...
- 2pEXgD0fZ5cF 4y agoAs somone who never really viewed systemd as a problem I'm starting to think the systemd "haters" were actually right, at least somewhat... Viewing Poettering as some kind malicious entity undermining projects sounds like a conspiracy theory. But now with him working for Microsoft his actions do look like a lot like the "embrace, extend, and extinguish" pattern to me. Yes, yes "Microsoft <3 Linux", of course... And now I am supposed to cheer for the groundwork for the creation of an allmighty authority with the ability to "sanction" some (parts of) operating systems, but not others?
- jart 4y agoI always thought this outcome was obvious. Systemd controls everything that happens before Linux boots. It controls everything that happens after Linux boots. Might as well call it GNU/Systemd at this point. It's the silent revolution no one wanted. The name itself implies a manifest destiny because System D is 100x greater than System V and they intentionally break POSIX compliance too. Now that the guy who owns the systemd project works for Microsoft, in addition to the fact that the Linux kernel now needs to be a Windows executable in order to boot, that really tells you all you need to know.
- frankzander 4y agoCan I turn it off? Tbh this TPM thingy doesn't solve any problem for me.
- sanxiyn 4y agoYes you can.
- retrobrandcool 4y agoI had a laptop with UEFI make it’s way into my tech junk stack sort of recently - pain in my ass!
- yjftsjthsd-h 4y agoEr, you mean secure boot? UEFI is fine IME
- vetinari 4y agoDepends. In theory it is fine, in practice it is a big ball of mud. I'm starting to like Apple's approach more. It allows to have multiple OSes installed and each to have different level of trust. In UEFI, the equivalent would be that you could have Secure-core like security for one installed instance, 3rd party UEFI-enabled Secure Boot for another and no Secure Boot for yet another installed OS. Unfortunately, in UEFI it is all-or-nothing instead.
- retrobrandcool 4y agoRight, it was secured(from a foreclosure auction). My collection is fairly modest, and getting more and more dated every day, so it was a bit of a curveball to run into something with not the usual BIOS. I think i sent it to GoodWill.
- athrowaway3z 4y agoI've never understood the need for all the complexity. Security should be built from the ground up from two physical ports. One is a file storage like SD card and one is a hasher/checker for the blobs that are read form that storage device. One of the blobs should be the CPU microcode. The system can be expanded with additional (tag,blobs). There. Solved every solvable use case. Okay, i lied. I do understand why there is a need for all the complexity. Some sysadmins and DRM believers think the complex solution makes their lives easier by being remotely controlled and being "good enough". Because nobody could ever care enough to tinker with 'baked in' secrets and if they do its above your pay-grade.
- TeMPOraL 4y agoNice try :). Computing built out of cryptographically secure cons cells. But no, this doesn't solve anything, because the root problem doesn't have anything to do with technology. The root problem is that people need to work together despite having conflicting goals and interests. Like, e.g., the major issue with trusted computing isn't trusted computing. Everyone would like their devices to be secure against unwanted software doing bad things. The conflict is over who owns the device in the first place. I'd like to own my PC, the very one I'm writing this comment on. So does Intel, Dell, Realtek, Microsoft, my bank, every news site, half a dozen governments, and countless criminals specialized in exploiting digital technology. Whether or not TC is good for me hinges entirely on the answer to the ownership question. As for complexity - it comes from the industry incrementally evolving technological solutions to what's a philosophical/sociological problem that doesn't have a theoretical solution yet (and might be unsolvable in general).
- gizzlon 4y ago"Considered attack scenarios and considerations: Evil Maid: [.. ] physical access to a storage device should [not] enable an attacker to read the user’s plaintext data [..]. [or] allow undetected modification/backdooring of user data or OS (integrity), or exfiltration of secrets." Am I misunderstanding, or is the the only attack scenario listed? Seems like a lot of work, complexity and potential problems of all sort to fix.. something quite minor? I mean: 1) Get a lock? 2) Will it actually stop an Evil Maid? I'm thinking of stuff like physical key-loggers, hidden cameras etc etc edit: fixed and shortened quote
- bakugo 4y ago> Seems like a lot of work, complexity and potential problems of all sort to fix.. something quite minor? Probably because the main goal isn't actually solving that problem. That's just the excuse used to let the trojan horse in and convince people to hand complete control of their devices over to corporations.
- evh 4y agoNow that's the most ominous title I've read all year, and it's a piece in favor of it? Maybe I've just read too many dystopian novels, but come on. I'm all in favor of secure boot as long as I can enroll my own keys, but remote attestation gets scary quickly.
- btschaegg 4y agoTotal sidenote: Funnily enough, the sentence as it was coined was positive before Huxley turned it around. (Shakespeare: The Tempest)
- fluidcruft 4y agoIt's possible to encrypt all of /boot while using SecureBoot. That was my solution. It's a little annoying to type the passphrase at boot, but it's entirely doable. I did the whole TPM thing previously on a Debian-only machine and it worked great until it stopped for some reason and I haven't had time to revisit. But on my latest machine I wanted to make sure Windows with SecureBoot worked and I was in a rush. So it's encrypted /boot for now. I figure the threat is now that someone could clone the drive and brute force the passphrase and then tamper with /boot.
- chabad360 4y agoI fail to see what all the panic is about. All of the SystemD tools mentioned here (iirc) don't actually rely much on SystemD proper and especially systemd-boot and the boot stub are just SystemD in name (I use both). But regardless, this entire article is about how to have an actually secure boot on Linux (and not remote attestation), something which is certainly good for the user. Otherwise you're actually more easily susceptible to malicious actors stealing your data on the system you "trust". None of the steps listed here require trusting anyone other than the TPM (which is admittedly a flaw so long as we cannot audit them) and you can even use your own keys in pretty much all cases (provided -as discussed in other comments- MS hasn't f'd that up). I personally use a boot-stub based booting method with my own SB keys (but ironically, don't encrypt my root, so go figure), so I can vouch for the fact that it was actually quite painless to setup. Please don't jump down the slippery slope before you actually try these methods and realize that this is just as easy to deploy (you only need to disable secure boot first) and certainly a more secure option than using shim and an unsecured initrd. Also, I don't understand where remote attestation entered the conversation here, and I also don't see why that can't be a community based thing (al la let's encrypt is now everyone's CA) where you can choose your providers or even roll it yourself.
- RetpolineDrama 4y ago> but ironically, don't encrypt my root, so go figure Oh man that takes me back. The last time I went down that rabbit hole was ~2015, I tried to implement a "fully encrypted" setup and started with Ubuntu (I know I know). Something something LUKS. I spent ~2 days tinkering with it and never got it to work, something with the setup flow was totally broken if you also tried to encrypt root (or boot? idk like I said it's been _years_). I also remember fun problems with grub. I was trying to dual-boot and the windows partition was using hardware-bitlocker (samsung SSD). Some kind of weird interaction was going on between grub, whatever the windows bootloader is called, and my motherboard's EFI I think. Anyways grub ended up fucking bitlocker up and I almost lost all my gaming saves. Had to use some kind of arcane recovery process to get back to being able to even _insert_ the key so the SSD would unlock and windows could continue booting. Ended up saying screw it after a few days and just going back to windows for my gaming PC, vowing to never try dual-boot again.
- stoplying1 4y agoSmh, the FUD is suffocating in here. And really, a round of applause for everyone butting into say they don't need this. Do you have a habit of doing this for all features? Sorry, but I expect my Linux install to be at least as secure as my Windows (Pro) installation. And without this, it's not. It's that simple. In years, most of you will be benefiting from this, it will become table stakes and the FUD will subside. It's hard to really read this thread. If you care about user freedom, this sure ain't got nothing to do with it. Other than giving me the freedom to have a more secure computer. Just sad to see the FUD cause people to just get so activated without even understanding the stakes at hand. (Think. It's not like MS is watching this feature to decide whether or not to allow user-key-enrollment on the ARM Surface).
- bayindirh 4y agoI just don’t trust a company and its employees which actively tried to kill Linux back in the day. Adding the fact that said company is designer, enforcer and gatekeeper of such technology makes everything more worrisome. Lastly, telling that people are spreading FUD against the company which defined and is synonymous with FUD is ironic. That’s all, Thank you.
- stoplying1 4y agoGreat, thats cool. I'm concerned about accessibility to general computing too. But this article is about an optional feature in an FOSS software that is only as good or bad as the distro using it. Please, you must understand, you devalue your point by demonstrating that you either don't understand the layering at play here, and where the real risks are, or you don't care to advocate in any sort of meaningful or compelling way. Instead, you just repeated FUD and waved your arms more. Again, about something we probably agree about, but is simply not at hand here. I mean the issue that you're worried about? How about the millions of capable smartphones being tossed because of closed bootloaders? Android manufacturers, Google's Nest and Chromecast products, and Apple's iOS devices here are far greater offenders. And just more insidious. My 3 year old phone that works damn fine is considered literal garbage by Google (no security updates, means I use Lineage, means I can't bank, watch Netflix, use credit card apps, and more). Microsoft has never used security features to invalidate my old hardware. Ever. Again, totally tangential from whether or not SystemD has first-rate support for this (mostly because at this point it's about UX and distro mechanics such that users and distros can freely secure their computers. The functionality to just lock-er-down has been here. For a decade). This issue is about capitalism, economic incentives, social politics, etc. But, I don't expect that conversation to play out on this site much. Finally, Pixel and Chromebook prove that secure computing AND user freedom CAN be respected and can be user-empowering. Please, if you care, advocate for their models. (Which, again, I can also do on all x86 Microsoft devices and Microsoft Surface ARM, at least, today).
- uri4 4y agoMy workaround for this problem was to use non encrypted USB flash drive for EFI and /boot partitions. It also contains encryption keys, main reason was to avoid entering passwords. Works pretty well, only problem kernel upgrade fails if usb key is not mounted. When I travel, there is no way to decrypt my computers, since keys are with me. When I arrive home, I insert keys, start all computers, upgrade packages (automated), remove keys...
- amarshall 4y agoI can’t tell if Poettering hasn’t read Brave New World, so the title is innocuous, or he has, and the title is frightening. That said, I’m in the camp of: this is good, and a lot of the comments here are FUD (aka Poettering probably hasn’t read Brave New World, or at least this isn’t that).
- Avamander 4y agoThird option, he chose that title to stoke the flame of all the inevitable FUD.
- totony 4y ago>Most popular Linux distributions generate initrds locally, and they are unsigned, thus not protected through SecureBoot (since that would require local SecureBoot key enrollment, which is generally not done), nor TPM PCRs. You can sign initrd and check it using (signed) grub. But yes you need local key enrollment. Maybe making this easier is the solution though? Instead of relying on Microsoft to be charitable with its keys. >No rollback protection (no way to cryptographically invalidate access to TPM-bound secrets on OS updates) Revoke the key used to sign either grub, the kernel or the initrd? >Unified Kernel Image UKI are systemd-specific and mostly a joke AFAICT. Linux supports embedding an initrd into its efi bin. Why make a new thing? The main object of this whole article is to make PCRs contain hashes of the current system state. Its only advantage is that it can be used to restrict some TPM access. To do that, it tries to introduce a new way to do things which adds nothing to the average user. This is mainly useful for distributions that want to have complete control on the boot process (most Linux distributions do not). A distribution can already do most (everything?) of what is suggested using rotating keys/key revocation locally, but this would introduce the possibility of forced attestation of local state. It's a plus for big organizations, but I fail to see how this improves the state of Linux for the user. At best it's an alternative to using local signing (which is already possible), at worst it's an entry into attestation of local state (DRM).
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- jaromilrojo 4y agoIMHO we should maintain GNU/Linux/BSD systems as tools that can free us, not entangle us or turn us into guinea pigs. The world is already full of proprietary systems, including the one produced by the employer of systemd. WSL has improved a lot in the past years, he should be focusing on that, or at least use that as a testing ground. Not confining new technology like systemd has lead to an infinite amount of CVEs to deal with in the past years, this could have been avoided by not allowing a tech prototype to bypass community adoption and impose itself as a ego-driven standard.
- mcint 4y agoGood previous discussions that cover, if not "motivations" (unknowable mental state) then some "consistent patterns of observable behavior". UDev & Gnome https://news.ycombinator.com/item?id=8416912 https://news.ycombinator.com/item?id=8416912 (8 years ago) udev, https://news.ycombinator.com/item?id=6066848 https://news.ycombinator.com/item?id=6066848 (9 years ago, same behavior reported) https://news.ycombinator.com/item?id=7211451 https://news.ycombinator.com/item?id=7211451 https://news.ycombinator.com/item?id=8203507 https://news.ycombinator.com/item?id=8203507 (8 years ago, community reports the same treatment) I applaud Pottering's systemd projects as a masterful career move at the same time that I shake my fist at them, and how they build a path to undermine free computing. They recentralize, and fragilize, the free software ecosystem. They build features that are not requested, with the premise of small, incremental benefits while taking away choice by making the pre-existing standard of interoperable decoupled components difficult-to-impossible to continue to use. This development pattern enforces deeper integration with their one blessed way, and tramples on the culture of the free software ecosystem, which the project efforts take part in, in all but ultimate aim. They do things that should not be done, although he's effective in creating and pursuing opportunities that advance the interests of Red Hat and now Microsoft. I like that free software has let me build and explore things without getting sign-off and approval from authority, while the existence and strength of free software means I get to enjoy some of its benefits even while using devices made by companies that do not pay-forward their free/open software founding roots, specifically that developer system configuration escape hatches are needed on macOS, and Windows, for competitive reasons. The ease of use, breadth of adoption, and creeping (and unnecessarily coupled) integration with widely used software are all small pennies, which "no one should object to", thrown to entice in front of the steamroller of centralized control of plausibly all software running (boot, OS, & applications) that makes founding fears of the free software community more likely to come to pass. https://www.gnu.org/philosophy/right-to-read.html https://www.gnu.org/philosophy/right-to-read.html Then again, > users are not contributors nor customers, and so > "They are not _technically_ part of the "community". https://news.ycombinator.com/item?id=7538184 https://news.ycombinator.com/item?id=7538184