Announcement

Collapse
No announcement yet.

Fedora "DIGLIM" Feature Proposal Drawing Mixed Reactions

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Fedora "DIGLIM" Feature Proposal Drawing Mixed Reactions

    Phoronix: Fedora "DIGLIM" Feature Proposal Drawing Mixed Reactions

    A proposal for Fedora 36 is to implement Digest Lists Integrity Module "DIGLIM" functionality as an optional feature for effectively providing remote attestation and/or secure boot at the application level...

    Phoronix, Linux Hardware Reviews, Linux hardware benchmarks, Linux server benchmarks, Linux benchmarking, Desktop Linux, Linux performance, Open Source graphics, Linux How To, Ubuntu benchmarks, Ubuntu hardware, Phoronix Test Suite

  • #2
    Ultimately it sounds like a feature most personal desktop/workstation users at least would likely end up disabling for being a burden on the user.
    I feel like that comment describes most every integrity feature.

    See the feature proposal which was raised by Huawei's Roberto Sassu.
    That makes a lot more sense. I can see how a company would want to ship a Linux/Fedora powered smart device and need a way to keep the user from messing with stuff so they can get 3rd parties on board...which is a dumb AF reason because Windows, but corporate gonna be corporate...but it could also keep the end-user and hackers from hacking smart cars.

    Comment


    • #3
      Originally posted by skeevy420 View Post

      I feel like that comment describes most every integrity feature.



      That makes a lot more sense. I can see how a company would want to ship a Linux/Fedora powered smart device and need a way to keep the user from messing with stuff so they can get 3rd parties on board...which is a dumb AF reason because Windows, but corporate gonna be corporate...but it could also keep the end-user and hackers from hacking smart cars.
      i like the idea of application allow listing, it does need to be smart though.

      "let me build softwate in the dir"

      be interesting with pip packages and steam games etc.

      but for a mum/corpo etc user never developing it might work ok

      Comment


      • #4
        Originally posted by boxie View Post

        i like the idea of application allow listing, it does need to be smart though.

        "let me build softwate in the dir"

        be interesting with pip packages and steam games etc.

        but for a mum/corpo etc user never developing it might work ok
        For end users without root/sudo I imagine all that, Steam, pip, whatever, will be handled similar to Silverblue -- Flats or sandboxes or AppImages (or, what I really think, a proprietary app store). So if the OS doesn't come with those tools you'll be at the mercy of the sys admin or OS provider (or just SOL).

        Here's how I see this: Take a Fedora install, add this, remove root, add 3rd party app management like Flatpak, and suddenly Fedora starts to become something like Android in regards to app management, root file system security, and system maintenance. It'll be interesting to see how this develops and where it gets used.

        Comment

        Working...
        X