Live data from Hacker News

Viewing profile — TommyTran732

TommyTran732

HN member
Joined
Fri, Oct 14, 2022, 3:23 PM UTC
HN karma
20
Public activity
29 items

About TommyTran732

System Administrator

Recent public activity

  1. comment
    Comment #47996192

    To be completely fair, any kind of sandboxing inside of Qubes's VMs do not mean much, because it is on X11. Any app can pwn any other app lol. With that being said, yeah, he's bein…

  2. comment
    Comment #47957720

    > what Purism is doing is moving the non-auditable part of the OS onto a separate storage device so that they can claim that the OS is "Fully Auditable" and FSF certified even thou…

  3. comment
    Comment #47956777

    > I see no effort from your side to come to some understanding or to clarify anything. Accusing me of your own sins. > What do you mean by "tampering" here? Is uploading firmware t…

  4. comment
    Comment #47954230

    Yeah, why are you selectively reading? This is after he admitted what I said was true. His only contention is that he thinks it's hard to know what the PCR values should be to fake…

  5. comment
    Comment #47954070

    Why do you copy paste the same thing over and over a bunch of times? Linking to an irrelevant post doesn't change how it works. Read the code posted above.

  6. comment
    Comment #47954053

    Since you copy pasta your response, I will link to my other comment and do a bit of copy pasta here: https://news.ycombinator.com/item?id=47953726 It is exactly how it works. Read …

  7. comment
    Comment #47953726

    Because it's true, and I know what he said, I am not confused at all. Did you not read anything at all? On the Librem laptop, the tampering is done by PureBoot and inject into /run…

  8. comment
    Comment #47950194

    It's basically taking the blobs that would be normally shipped with the OS in a sensible manner, shuffle it around, then calling it "free" while the same blobs would still be there…

  9. comment
    Comment #47950063

    The SOC still has firmware baked in as per usual. And the firmware for Bluetooth/Wifi is loaded in by having the initramfs read it from the NOR flash, mount it in /lib/firmware, th…

  10. comment
    Comment #47949803

    > It's just physically impossible to defend from tracking, when the phone has networking connections on. Not even on all-mighty GrapheneOS. I can use GrapheneOS with the global mic…

  11. comment
    Comment #47949589

    The developer of Heads admitted that if someone tampers with the boot block and falsifies the measurements Heads cannot protect the device right on the Qubes forum. Why won't you l…

  12. comment
    Comment #47949532

    Which blobs are running on the Librem 5 CPU? Which blobs are running on GrapheneOS CPU? Both the Pixel and Librem 5 have firmware baked into the SoC that is executed. On GrapheneOS…

  13. comment
    Comment #47947395

    Quite frankly, the whole Librem ecosystem is significantly less "open" than GrapheneOS or any desktop Linux variant to anyone who look at things objectively instead of using weird …

  14. comment
    Comment #47880225

    > You never could answer to them. I did reply to them plenty of times. Here you go doing the exact same thing again - ignoring 100% of what's being said, then claiming "no one can …

  15. comment
    Comment #47880070

    Man, if this entirely thread of people calling out how ridiculous the implementation is and the killswitch not actually working in practice isn't enough to convince you, nothing ev…

  16. comment
    Comment #47871383

    Not entirely sure if the chip they are using (WM8962) can be reconfigured as a mic or not... it probably can't. But yes, the speaker is still active even when the mic is toggle off…

  17. comment
    Comment #47871229

    Oh he's already done that when I explained to him how stuff like PureBoot has circular logic and doesn't actually work on Qubes forum already. Unfortunately he will just ignore eve…

  18. comment
    Comment #47869879

    And what good is the phone when 3 switches are off? You think that people buy a phone with a "mic killswitch" expects to have to turn off practically everything including internet …

  19. comment
    Comment #47856624

    Important to note that users only stopped getting updates, the phones were not bricked and they can reinstall the OS signed with the new key. CopperheadOS was always's Micay's proj…

  20. comment
    Comment #47855622

    > Their microphone kill switch also doesn't prevent audio recording It doesn't prevent audio recording in the super paranoid "oh, the whole phone has been compromised" scenario bec…

  21. comment
    Comment #47855294

    > I said multiple times that I exclusively run trusted apps on the phone. I use Qubes for untrusted staff. Do you understand that threat models can vary? By that logic, you might a…

  22. comment
    Comment #47854892

    You have been saying this sort of stuff on the Qubes forum and a bunch of other places for awhile now. Hardware kill switches are nice-to-have, but they are significantly less impo…

  23. comment
    Comment #47854244

    So what exactly would you have done? Risk the key being taken over by a shady entity? Does the alternative really scream "mature, stable, and thoughtful" to you?

  24. comment
    Comment #36301510

    Oh wow. I will update the post later today. Thanks for pointing it out!

  25. comment
    Comment #36301454

    Are you TAJ? The only people who refer to me as B0risGrishenko (my old Reddit account for a few months) are either TAJ or the crazy people on r/privatelife who have no idea what th…