Post B7Yptn0YPE0eSo9yBE by Nocta_Senestra@eldritch.cafe
 (DIR) More posts by Nocta_Senestra@eldritch.cafe
 (DIR) Post #B7YmRKprG1Cf7KtgYq by lumi@snug.moe
       2 likes, 2 repeats
       
       we should actively resist remote attestation in all its formsif you develop remote attestation software, please reconsiderif you package software that enables remote attestation, patch out the remote attestation capabilitiesi feel systemd may get support for this in the future, and we should patch it out
       
 (DIR) Post #B7Ymf3GVNbZcg7ty6a by lumi@snug.moe
       2 likes, 0 repeats
       
       of course, if you can afford to move away from systemd, please do. we need more diversitybut if you can't, patch out very problematic parts like this
       
 (DIR) Post #B7YmuTf1WZDyt0j332 by lumi@snug.moe
       0 likes, 0 repeats
       
       doing a bit more research: www.ietf.org/rfc/rfc9334.html... yikescdn.prod.website-files.com/63c54a346e01f30e726f97cf/69ce364a893d698d7d5622eb_OC3%202026%20%E2%80%93%20Remote%20Attestation%20of%20Immutable%20Operating%20Systems%20built%20on%20systemd.pdfalso yikes
       
 (DIR) Post #B7YmxnSkMDo1AaZ9Vo by lumi@snug.moe
       0 likes, 0 repeats
       
       "Remote Attestation of Immutable Operating Systems built on systemd"ew ew ew yikes get it away from me. this shit needs to be objected to as hard as possible
       
 (DIR) Post #B7YpCrDyqx2H5Zy6Wu by TheOneDoc@tech.lgbt
       1 likes, 1 repeats
       
       @lumi isn't that what Pottering's new Company is doing? https://www.phoronix.com/news/AmutableAlways follow the money and you will find the source of the bullshit.
       
 (DIR) Post #B7YpF3nT52EOf1cMj2 by goowose@mk.absturztau.be
       1 likes, 0 repeats
       
       @lumi@snug.moe they unironically called it rats
       
 (DIR) Post #B7Yptn0YPE0eSo9yBE by Nocta_Senestra@eldritch.cafe
       1 likes, 0 repeats
       
       @lumi I'm not sure I understand what it is exactly
       
 (DIR) Post #B7YptnK3EjbbRHHXZQ by lumi@snug.moe
       0 likes, 0 repeats
       
       @Nocta_Senestra remote attestation tech (a kind of drm) are things like google play integritybasically, you use specialized hardware to prove to a remote server that your system is in the state that the remote server expects it to bethis removes all autonomy from the user; they don't get a choice on what software they run anymoreapplications using it will just refuse to start (or their connections with the remote server will not work, as you cannot prove anymore that the software you run is what it wants you to run)this is cryptographically verified so it is very difficult to impossible to get around
       
 (DIR) Post #B7Yq0OOoIbQuATecGu by cancername@mas.to
       1 likes, 0 repeats
       
       @lumi remote attestation has some pretty good use cases but it's easy to abusesystemd is entirely the wrong thing to build this on imo and i do NOT trust the systemd people to implement this competently
       
 (DIR) Post #B7Yq0OdLQZ3itYSDvU by lumi@snug.moe
       0 likes, 0 repeats
       
       @cancername yes it has some cool use cases, but it's not worth it to develop it. we should not accept itit's too easy to abuse and the fallout is massive, while the pros are just small nice to haves without a huge impact on anything
       
 (DIR) Post #B7YrCF9ua1HEwGtsH2 by Nocta_Senestra@eldritch.cafe
       1 likes, 0 repeats
       
       @lumi Ah yeah I see I hate that kind of bullshit ><"Always used a phone without google services, always a pain with a government relying on it for a lot of thingsI didn't know it was called like that thank you for educating me!
       
 (DIR) Post #B7YrH4TPjfXPFLKAgS by lumi@snug.moe
       0 likes, 0 repeats
       
       @Nocta_Senestra make sure to educate others, expand the movement against it :3stay loud, comrade
       
 (DIR) Post #B7YtWt04MQ26CjGe0G by mi@awawa.cat
       1 likes, 0 repeats
       
       Hm tbh if you find a recording of his LAS 2026 keynote the “Amutable” will make some sense. You may find subtle clues in it as to whether remote attestation is thought as a part of that or not
       
 (DIR) Post #B7ZGjGQROCjFHGTQky by cancername@mas.to
       0 likes, 0 repeats
       
       @kkarhan @lumi @Netzblockiererthat is not! what remote attestation is. remote attestation just means that you have some piece of code running on a machine, and a second computer can verify that this piece of code is what's it expects, nothing more, nothing less.there are legitimate use cases for this. if you are, for example, at risk of OS compromise, you can use remote attestation to check that nobody tampered with your OS.but this can also be abused, by companies to make their software harder for users to change, by banking apps discouraging uses they don't approve of.
       
 (DIR) Post #B7ZGjGeyWAM40LH2PY by cancername@mas.to
       0 likes, 0 repeats
       
       @kkarhan few people need or want remote attestation, but sometimes it is useful.
       
 (DIR) Post #B7ZGjGpbscrUXKFWzI by lumi@snug.moe
       0 likes, 0 repeats
       
       @cancername @kkarhan it's just way too abusable, though. so it's safer to object to it all and have proper secure/verified boot
       
 (DIR) Post #B7ZHK0nETOVXVcenY0 by cancername@mas.to
       1 likes, 0 repeats
       
       @lumi problem being that verified or measured boot is a prerequisite to local attestation (which we want) and remote attestation (which we don't want)
       
 (DIR) Post #B7ZHPFdYi8sYzjdA5g by lumi@snug.moe
       0 likes, 0 repeats
       
       @cancername you can make sure that a security boundary means attestation capabilities are never given to userspaceor only to system userspace processes, never applications
       
 (DIR) Post #B7ZIUKf7YSKjyxLdRI by cancername@mas.to
       1 likes, 0 repeats
       
       @lumi you're right, but that's how we get stuff like super-locked-down android which is the type of thing we're trying to prevent :/as far as I can tell it would also prevent grapheneos' implementation of remote attestation which I do like
       
 (DIR) Post #B7ZIWkffpDu3E6lC7s by lumi@snug.moe
       0 likes, 0 repeats
       
       @cancername yeah... maybe in the current political climate it is best to just not have any of this verified boot stuff...