Platform security in NixOS (asg2024) episode artwork

EPISODE · Sep 25, 2024 · 20 MIN

Platform security in NixOS (asg2024)

from Chaos Computer Club - archive feed (high quality) · host Ryan Lahfa, Niklas Sturm

You may have heard about this weird distribution, NixOS, that breaks compatibility with /usr. This talk explores the properties inherent to NixOS, focusing on its distinct approach to package management and system configuration. Learn how these principles combine with general upstream efforts at bringing TPM2, Secure Boot and more to your Linux distribution. Everything you wanted to know about why NixOS do things a certain way will be answered here. The idea is that you get out of this talk understanding the different compromises done by the NixOS community and what they get out of it. We will cover https://github.com/nix-community/lanzaboote which is a Rust UEFI stub similar to systemd-stub with fewer features but with one unique special feature for NixOS, similar to UKI addons. We will also do a status report of where NixOS stands in terms of adoption of systemd features such as systemd-pcrlock. Licensed to the public under https://creativecommons.org/licenses/by/4.0/de/ about this event: https://cfp.all-systems-go.io/all-systems-go-2024/talk/UQ3CYU/

Episode metadata supplied by the publisher feed · Published Sep 25, 2024

Embed this episode

NOW PLAYING

Platform security in NixOS (asg2024)

0:00 20:55

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Chaos Computer Club - archive feed (high quality)?

This episode is 20 minutes long.

When was this Chaos Computer Club - archive feed (high quality) episode published?

This episode was published on September 25, 2024.

Can I download this Chaos Computer Club - archive feed (high quality) episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!