6 ms·
What is the endgame here? Obviously "heightened security" in some kind of sense, but to what end and what mechanisms? What is the scope of the work? Is this wor
by shit_game 8mo ago
What is the endgame here? Obviously "heightened security" in some kind of sense, but to what end and what mechanisms? What is the scope of the work? Is this work meant to secure forges and upstream development processes via more rigid identity verification, or package manager and userspace-level runtime restrictions like code signing? Will there be a push to integrate this work into distributions, organizations, or the kernel itself? Is hardware within the scope of this work, and to what degree?
The website itself is rather vague in its stated goals and mechanisms.
- storystarling 8mo agoI suspect the endgame is confidential computing for distributed systems. If you are running high value workloads like LLMs in untrusted environments you need to verify integrity. Right now guaranteeing that the compute context hasn't been tampered with is still very hard to orchestrate.
- yencabulator 8mo agoThat endgame has so far been quite unreachable. TEE.fail is the latest in a long sequence of "whoever touches the hardware can still attack you". https://news.ycombinator.com/item?id=45743756 https://news.ycombinator.com/item?id=45743756 https://arstechnica.com/security/2025/09/intel-and-amd-trusted-enclaves-the-backbone-of-network-security-fall-to-physical-attacks/ https://arstechnica.com/security/2025/09/intel-and-amd-trust...
- LooseMarmoset 8mo agoNo, the endgame is that a small handful of entities or a consortium will effectively "own" Linux because they'll be the only "trusted" systems. Welcome to locked-down "Linux". You'll be free to run your own Linux, but don't expect it to work outside of niche uses.
- mariusor 8mo agoPersonally for me this is interesting because there needs to be a way where a hardware token providing an identity should interact with a device and software combination which would ensure no tampering between the user who owns the identity and the end result of computing is. A concrete example of that is electronic ballots, which is a topic I often bump heads with the rest of HN about, where a hardware identity token (an electronic ID provided by the state) can be used to participate in official ballots, while both the citizen and the state can have some assurance that there was nothing interceding between them in a malicious way. Does that make sense?
- c0l0 8mo agoNo.
- mariusor 8mo agoWhy not? Being terse does not make one right...
- fragmede 8mo agohttps://xkcd.com/2030/ https://xkcd.com/2030/
- mzajc 8mo agoOff the top of my head, because - You're just moving your trust elsewhere, this time to a private corporation (whoever makes the CPU / TPM / other "trusted" component). - This doesn't guarantee voter anonymity the way paper ballots do. Considering the analog hole and the complexity of computers, I can think of a billion ways a motivated and resourceful Mallory could to connect someone to their ballot.
- 8mo ago