4 ms·
>no upgrade path to Windows 11 because my CPU was 5 years too old apparently. Let's be real. It's because new systems support DRM and Microsoft has been captu
by stackghost 8mo ago
>no upgrade path to Windows 11 because my CPU was 5 years too old apparently.
Let's be real. It's because new systems support DRM and Microsoft has been captured by the media company lobby.
- realusername 8mo agoOf course it is, there's no real requirement to have a TPM, plenty of people made a version with that requirement patched out and the system works fine.
- badc0ffee 8mo agoIf they didn't, people might start capturing copyrighted streaming content and sharing torrents of it. We cannot allow that to happen.
- stackghost 8mo agoThe scary part of HN these days is that I can't tell if you're being serious or sarcastic
- donmcronald 8mo agoIt’s way worse than that. It’s for verified identity and attestation.
- WD-42 8mo agoWe had that announcement of a new "Verifiable" Linux project from Pottering, other kernel devs, and a bunch of ex-microsoft employees yesterday. Gives me the heebie jeebies.
- stackghost 8mo agoYeah I caught a lot of downvotes for coming out early against it.
- jofla_net 8mo agoHow dare you think for yourself in 2026! Remote Attestation of Immutable Operating Systems built on systemd Its the "remote" thing that has no place in personal computing, or rather, computing that is to extend one's own autonomy, or agency. Its no one's damn business whether my system is attested or not! I mean, sure theres certainly benefits for me knowing if its attested, but the other road is one of ruin, and will basically be the chains of the future.
- hparadiz 8mo agoRemote attestation is just generating a random blob on the remote side and then making the tpm 2.0 module on a computer sign the blob with a private key. You then provide the signature and the public key to the remote for verification. That enrolls that device. After that you can "verify" with a new binary blob and validate a new signature came back with the same key. That full loop is remote attestation. The idea is your disk didn't get moved to another computer. It's a security thing that Linux does need and is capable of being fully open source. It has nothing to do with drm.
- jiggawatts 8mo agoIt has everything to do with DRM. It’s not “dual use” technology. It has one use, and this is it.
- hparadiz 8mo agoWe're gonna be using this to validate someone didn't move your login to another device. Which will protect you from session hijacking. Your work stuff will start requiring it. Your media accounts will too. Or else linux will simply be locked out from major services. DRM is already in your browser. And literally has no connection to identity attestation.
- WD-42 8mo agoWho is “we”? So we can know who to avoid.