The other article on their blog introduces a systemd module that not only collects all hardware information, but also signs it with TPM before transmission [0].
I'm not even sure it makes much sense in datacenter conditions. And once it gets onto computers of the regular users, it would be very easy to repurpose it for spyware.
Only an idiot would think that systemd-report is malware. Seriously, do you not understand that this is a service that you would only enable if you need it? It’s not magically sending data to bad guys.
And signing the reports using the TPM doesn’t make it spyware either. It merely allows you to verify that the report came from one of your own machines, and one with a known state. If a bad guy hacks the machine the signature will reveal that the machine was hacked.
And there’s no way to turn a TPM signature into DRM. Suppose Netflix wanted to verify that your computer could not save a copy of a Netflix stream to disk. They could get a TPM signature on some data and use that to verify that your computer was compliant with the rules, right? Wrong! Every single update you ever install will change the signature. BIOS/UEFI updates, kernel updates, bootloader configuration, rolling updates to packages. It all changes the TPM state and thus the signatures. To verify any of that Netflix would have to know every single combination of OS version and BIOS version and motherboard model and so on. In practice all they’d get is a cacophony of noise.
TPM signatures are only useful for verifying the state of your own computers, and only because you control when and how the upgrades happen. And by “you” I really mean large enterprises with tens of thousands of computers (both real and virtual) to manage and a dedicated staff to keep track of everything.
> TPM signatures are only useful for verifying the state of your own computers, and only because you control when and how the upgrades happen. And by “you” I really mean large enterprises with tens of thousands of computers (both real and virtual) to manage and a dedicated staff to keep track of everything.
Yes! And part of what makes this new systemd tooling so exciting to a sysadmin like me is that it’s making this very useful stuff available to less-enterprisey shops too.
bananaquant · · focus · HN ↗
I'm not even sure it makes much sense in datacenter conditions. And once it gets onto computers of the regular users, it would be very easy to repurpose it for spyware.
[0]: <a href="https://amutable.com/blog/it-starts-upstream-systemd-report" rel="nofollow">https://amutable.com/blog/it-starts-upstream-systemd-report
db48x · · focus · HN ↗
Also, most consumer computers don’t have a TPM.
bananaquant · · focus · HN ↗
<a href="https://www.techtimes.com/articles/319581/20260703/steam-hardware-survey-june-2026-windows-11-tops-70-amd-closes-intel.htm" rel="nofollow">https://www.techtimes.com/articles/319581/20260703/steam-har...
According to the article, ~70% of Steam users are on Windows 11, so have TPM 2.0. That is already the majority.
db48x · · focus · HN ↗
bananaquant · · focus · HN ↗
db48x · · focus · HN ↗
And signing the reports using the TPM doesn’t make it spyware either. It merely allows you to verify that the report came from one of your own machines, and one with a known state. If a bad guy hacks the machine the signature will reveal that the machine was hacked.
And there’s no way to turn a TPM signature into DRM. Suppose Netflix wanted to verify that your computer could not save a copy of a Netflix stream to disk. They could get a TPM signature on some data and use that to verify that your computer was compliant with the rules, right? Wrong! Every single update you ever install will change the signature. BIOS/UEFI updates, kernel updates, bootloader configuration, rolling updates to packages. It all changes the TPM state and thus the signatures. To verify any of that Netflix would have to know every single combination of OS version and BIOS version and motherboard model and so on. In practice all they’d get is a cacophony of noise.
TPM signatures are only useful for verifying the state of your own computers, and only because you control when and how the upgrades happen. And by “you” I really mean large enterprises with tens of thousands of computers (both real and virtual) to manage and a dedicated staff to keep track of everything.
jcgl · · focus · HN ↗
Yes! And part of what makes this new systemd tooling so exciting to a sysadmin like me is that it’s making this very useful stuff available to less-enterprisey shops too.