The other article on their blog introduces a systemd module that not only collects all hardware information, but also signs it with TPM before transmission [0].
I'm not even sure it makes much sense in datacenter conditions. And once it gets onto computers of the regular users, it would be very easy to repurpose it for spyware.
Only an idiot would think that systemd-report is malware. Seriously, do you not understand that this is a service that you would only enable if you need it? It’s not magically sending data to bad guys.
And signing the reports using the TPM doesn’t make it spyware either. It merely allows you to verify that the report came from one of your own machines, and one with a known state. If a bad guy hacks the machine the signature will reveal that the machine was hacked.
And there’s no way to turn a TPM signature into DRM. Suppose Netflix wanted to verify that your computer could not save a copy of a Netflix stream to disk. They could get a TPM signature on some data and use that to verify that your computer was compliant with the rules, right? Wrong! Every single update you ever install will change the signature. BIOS/UEFI updates, kernel updates, bootloader configuration, rolling updates to packages. It all changes the TPM state and thus the signatures. To verify any of that Netflix would have to know every single combination of OS version and BIOS version and motherboard model and so on. In practice all they’d get is a cacophony of noise.
TPM signatures are only useful for verifying the state of your own computers, and only because you control when and how the upgrades happen. And by “you” I really mean large enterprises with tens of thousands of computers (both real and virtual) to manage and a dedicated staff to keep track of everything.
> Seriously, do you not understand that this is a service that you would only enable if you need it?
There are broad classes of Linux-powered devices where you don't get to enable or disable components. They come programmed by the manufacturer to lock the user out of meaningfully owning and using the hardware. And if it is possible to alter them, the user will lose functionality like logging into remote services and running apps that self-selected to enable remote attestation. All the things that previously worked.
> It merely allows you to verify that the report came from one of your own machines... And by “you” I really mean large enterprises with tens of thousands of computers...
Following your exact reasoning, any computer manufacturer of a meaningful scale can indeed turn TPM signatures into DRM. All that is left for them to do is to provide some pre-approved kernel versions and updates to them. They will remotely verify integrity of the system and the system is going to verify whatever it is programmed to verify.
It can absolutely do worse things than your example of preventing Netflix piracy. How about checking that all the hardware components are approved by the manufacturer, down to their serial numbers? Apple and John Deere love that. With this tech, others will be empowered to do the same. Even worse, computers that were built independently will become useless for all of the use cases where such remote attestation is required.
There are many, many second-order effects of this technology and not a single socially positive one.
bananaquant · · focus · HN ↗
I'm not even sure it makes much sense in datacenter conditions. And once it gets onto computers of the regular users, it would be very easy to repurpose it for spyware.
[0]: <a href="https://amutable.com/blog/it-starts-upstream-systemd-report" rel="nofollow">https://amutable.com/blog/it-starts-upstream-systemd-report
db48x · · focus · HN ↗
Also, most consumer computers don’t have a TPM.
bananaquant · · focus · HN ↗
<a href="https://www.techtimes.com/articles/319581/20260703/steam-hardware-survey-june-2026-windows-11-tops-70-amd-closes-intel.htm" rel="nofollow">https://www.techtimes.com/articles/319581/20260703/steam-har...
According to the article, ~70% of Steam users are on Windows 11, so have TPM 2.0. That is already the majority.
db48x · · focus · HN ↗
bananaquant · · focus · HN ↗
db48x · · focus · HN ↗
And signing the reports using the TPM doesn’t make it spyware either. It merely allows you to verify that the report came from one of your own machines, and one with a known state. If a bad guy hacks the machine the signature will reveal that the machine was hacked.
And there’s no way to turn a TPM signature into DRM. Suppose Netflix wanted to verify that your computer could not save a copy of a Netflix stream to disk. They could get a TPM signature on some data and use that to verify that your computer was compliant with the rules, right? Wrong! Every single update you ever install will change the signature. BIOS/UEFI updates, kernel updates, bootloader configuration, rolling updates to packages. It all changes the TPM state and thus the signatures. To verify any of that Netflix would have to know every single combination of OS version and BIOS version and motherboard model and so on. In practice all they’d get is a cacophony of noise.
TPM signatures are only useful for verifying the state of your own computers, and only because you control when and how the upgrades happen. And by “you” I really mean large enterprises with tens of thousands of computers (both real and virtual) to manage and a dedicated staff to keep track of everything.
bananaquant · · focus · HN ↗
There are broad classes of Linux-powered devices where you don't get to enable or disable components. They come programmed by the manufacturer to lock the user out of meaningfully owning and using the hardware. And if it is possible to alter them, the user will lose functionality like logging into remote services and running apps that self-selected to enable remote attestation. All the things that previously worked.
> It merely allows you to verify that the report came from one of your own machines... And by “you” I really mean large enterprises with tens of thousands of computers...
Following your exact reasoning, any computer manufacturer of a meaningful scale can indeed turn TPM signatures into DRM. All that is left for them to do is to provide some pre-approved kernel versions and updates to them. They will remotely verify integrity of the system and the system is going to verify whatever it is programmed to verify.
It can absolutely do worse things than your example of preventing Netflix piracy. How about checking that all the hardware components are approved by the manufacturer, down to their serial numbers? Apple and John Deere love that. With this tech, others will be empowered to do the same. Even worse, computers that were built independently will become useless for all of the use cases where such remote attestation is required.
There are many, many second-order effects of this technology and not a single socially positive one.