top | item 41676646

Arch Linux and Valve Collaboration

160 points| jrepinc | 1 year ago |lists.archlinux.org

21 comments

order
[+] uyzstvqs|1 year ago|reply
> Valve is generously providing backing for two critical projects that will have a huge impact on our distribution: a build service infrastructure and a secure signing enclave.

It sounds like Valve is investing in the security of Arch Linux's build infrastructure to prevent supply chain attacks.

[+] cyanmagenta|1 year ago|reply
I really hope Arch moves to a model like Debian where all packages are built by a central build server. The current strategy—having dozens of different developers compile stuff on their laptops, sign it personally, and then upload the binary blob—leaves a bit to be desired for obvious reasons.
[+] AmpsterMan|1 year ago|reply
As a novice Arch user, I never realized this is why I needed to update keys often
[+] wiktor-k|1 year ago|reply
That's exactly what's happening.
[+] tetris11|1 year ago|reply
If builds are reproducible, what's the issue?
[+] Sabinus|1 year ago|reply
It's incredible how, as a privately owned company, Valve avoids the profit chasing short termism of the publically traded companies.
[+] beeflet|1 year ago|reply
>secure signing enclave

wonder what this involves? TPM stuff?

[+] T3OU-736|1 year ago|reply
Usually, at that level, an HSM (Hatdware Security Module (ex: https://www.entrust.com/products/hsm), but also a fair number of processes and procedures around things like private key generation, key attestation, key verification, certificate renewals, etc etc etc).

There are some parallels with a TPM, but also a great deal of divergence (more so than in common, really).

[+] brnt|1 year ago|reply
I hope a stable branch may result.
[+] RandomThoughts3|1 year ago|reply
Arch already has a stable branch. If you mean a branch which doesn’t update packages and where "maintainers" pretend they back port "essential" fixes by randomly patching what they ship, I hope it never happens because it would mean Arch is truly dead.
[+] Am4TIfIsER0ppos|1 year ago|reply
Stability is attained by never updating.