The creator of systemd (Lennart Poettering) has recently created a new company dedicated to bringing hardware attestation to open source software.

What might this entail? A previous blog post could provide some clues:

So, let’s see how I would build a desktop OS. The trust chain matters, from the boot loader all the way to the apps. This means all code that is run must be cryptographically validated before it is run. This is in fact where big distributions currently fail pretty badly. This is a fault of current Linux distributions though, not of SecureBoot in general.

If this technology is successful, the end result could be that we would see our Linux laptops one day being as locked down as an Iphone or Android device.

There are lots of others who are equally concerned about this possibility: https://news.ycombinator.com/item?id=46784572

  • darthinvidious@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    edit-2
    3 hours ago

    An alternative to secureboot that isn’t secureboot but behaves like it. Wonderful 🙄

    Another Poettering “masterpiece” ready to be gobbled up by his fanbase who will flock towards the new and shiny toy that forgoes the things that actually work fine or aren’t solving an actual problem with 99% of whatever it’s used by. Great 🙄 🙄 🙄

    EDIT:

    No doubt this will be his opportunity to force everyone off grub and use systemd as the bootloader across major distros. As valid as it may be to succeed grub, surely systemd is not the answer to this.

  • RVGamer06@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    3
    ·
    4 hours ago

    Can’t wait to not be able to VR game with my Nvidia GPU on Linux cuz they can’t be arsed to properly sign their damn proprietary drivers.

  • tabular@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    14 hours ago

    Who decides what SecureBoot considers trustworthy? If SecureBoot is controlled by someone else then it can be used against the user. The aversion to SecureBoot is justified.

  • pHr34kY@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    15 hours ago

    I wonder if this would allow an anti-cheat system to get acceptable trust of a system without having to access ring 0.

    Of course, we’d then need the OS / kernel images to be signed. I think most gamers run stock kernels anyway.

    I just don’t want see the garbage that is the Android Play Store where apps refuse to run because we run an OS that isn’t profitable to Google.

    • thatonecoder@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 hours ago

      Anti-cheats do NOT need to be client-side… Polar is server-sided, yet it has practically killed cheating in Minecraft.

    • cmhe@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 hours ago

      That would actually be the wrong thing to want. In an ideal system trust would always begin by the owner of the hardware, where possible, not the software or vendor they decide to trust.

      First the person that bought the system should take the ownership by overwriting the previous owners keys, and from there start signing the vendors key, they decide to put their trust in. Because it is important that the system is trustworthy to the end user/owner first.

      Any anti-cheat mechanism relies on not trusting the person that owns the hardware, and why would that be good?

    • namingthingsiseasy@programming.devOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      10 hours ago

      I just don’t want see the garbage that is the Android Play Store where apps refuse to run because we run an OS that isn’t profitable to Google.

      I think the possibility that this could happen is dangerously high.

      Everything starts with good intentions. Everything ultimately leads to locking end users out of their personal freedoms.

  • mlg@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    12 hours ago

    I forgot already but doesn’t he work for MSFT now?

    I swear the moment he got a new job is when he came out with run0

  • Retail4068@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    6
    ·
    edit-2
    15 hours ago

    The anti MS morons who don’t understand secure boot and just regurgitating we hate this because it’s associated with them are out 🙄