6 ms·
Windows security models and policies are the enemy, not remote attestation (RA). RA is a technology that has its fair use, and can be desired for other systems
by aplanas 4y ago
Windows security models and policies are the enemy, not remote attestation (RA).
RA is a technology that has its fair use, and can be desired for other systems, like in Linux. With a pure RA system your services can decide to trust or not those devices on your network that can be compromised, and report to other devices that there is something suspicious.
As anything, this can be used properly to increase the security of your edge architecture, or wrongly to limit the users actions.
Let me put another example. With RA I should be able to authorize validated systems in my R&D VPN. If you are using your own laptop with the company certificate, and the verifier tag the systems as "unknown" or "unhealthy", it will not allow the access to the internal network, but sure you can still use your laptop for anything else. This, IMHO, is a fair use of this technology.
- POPOSYS 4y agoIs it possible to realize this with Linux systems / networks today? Do you have any good project / description / URL? Thanks!
- ajvs 4y agoGrapheneOS remote attestation arguably fits this criteria by being built on Android.
- aplanas 4y agoIt is still under development, but try Keylime[1]. They have also a nice agent written in Rust[2] with low footprint. I write some notes[3] about how to use it in openSUSE MicroOS / Tumbleweed, but can be extrapolated to many other distributions too. [1] https://github.com/keylime/keylime https://github.com/keylime/keylime [2] https://github.com/keylime/rust-keylime https://github.com/keylime/rust-keylime [3] https://en.opensuse.org/Portal:MicroOS/RemoteAttestation https://en.opensuse.org/Portal:MicroOS/RemoteAttestation
- fulafel 4y agoYes, lots of Linux devices apply it like that today: You can't use your banking app or consume DRM crippled media on your Android phone if you have root or run a open source Android distribution.
- Aeolun 4y ago> if you have root Because god forbid you have control of your own PC?
- Ycombigatorz 4y agoBecause if you have control, so many numerous other parties.
- npteljes 4y agoYep! Basically, it's safer if you don't own your PC. Think about users with a million toolbars and Bonzi Buddy installed. Of course, the system for it is rudimentary, and puts a disproportionate amount of control in the hands of providers. And that works very well for them too.
- 29athrowaway 4y ago
- TheOtherHobbes 4y agoIn a sane society these features would allow secure voting. In this one... that's not what they'll be used for. This is the end game for the corporate internet. Not only can all your activity be logged, but if any of it is unwelcome - on any scale, from family to school to work to country to world - you can be locked out.