←back to thread

596 points pimterry | 2 comments | | HN request time: 0s | source
Show context
Santosh83 ◴[] No.36862751[source]
Maybe I'm wrong but Web Attestation will also be a death knell for Linux devices (not Android/Chrome OS) as far as being able to use them as equal clients to use the Web goes. They're simply too diverse and 'hackable' as a plotform for remote attestation to work reliably and thus they'll be excluded altogether (except a few 'blessed' distros that will then become industry controlled, and not Linux in spirit anymore).
replies(7): >>36862825 #>>36862993 #>>36863025 #>>36863063 #>>36863230 #>>36864206 #>>36865119 #
smoldesu ◴[] No.36862825[source]
If this happens, I expect the majority of Windows and Android devices to stop working too. They are also a diverse and hackable platform that is apparently insufficient for a future where I have to attest to owning certain hardware.

> except a few 'blessed' distros that will then become industry controlled, and not Linux in spirit anymore

You know, I hear this a lot but seldom hear the details of how it might happen. Industry-controlled UNIX is the reason Linux exists - if you take the spirit away from Linux, it gets forked into another community project. Unless you're stripping it of it's GPL license, Linux will be "Linux in Spirit" until it stops being used altogether.

replies(4): >>36862879 #>>36862948 #>>36863069 #>>36863354 #
fsniper ◴[] No.36862948[source]
If people can't use their prefered Linux distros to do banking, or can't connect to social networks,email providers, music streaming services and so on this will mean practically they are forced to switch distros. Which would eventually add more control power to some Distros to what goes into development and what not.

You can see systemd and it's history about how it hold power.

replies(2): >>36862963 #>>36863225 #
JohnFen ◴[] No.36863225[source]
Or run one of the "blessed" or "compromised" (depending on your point of view) distros in a VM purely for those types of things.
replies(2): >>36863289 #>>36871219 #
Avamander ◴[] No.36863289[source]
That's the point where you'd need the VM itself to be attested for it to work. Hyper-V kinda does it already with Shielded Windows VMs.

With the advent of SEV, you won't even be able to look at the stuff your hypervisor is running.

replies(1): >>36863690 #
1. fsniper ◴[] No.36863690[source]
Also there is no guarantee that "attestation" won't require your software to run on the physical hardware and not on a vm.
replies(1): >>36863945 #
2. Avamander ◴[] No.36863945[source]
True, but virtualization is big enough (including Microsoft's own Windows365 offerings) that passing "trust" down into VMs will be done. And with SEV there isn't even a way to tamper with things after the attestation process has been completed.