Live data from Hacker News

Viewing profile — mkopec

mkopec

HN member
Joined
Fri, Aug 06, 2021, 4:07 PM UTC
HN karma
181
Public activity
52 items

About mkopec

Open-source firmware engineer.

All opinions mine unless expressly stated otherwise.

Recent public activity

  1. story
  2. comment
    Comment #42950482

    > If all DVD players came with watermark detection instead of copy protection That is an enormous "if". Do you think Microsoft is going to or is able to enforce this on every singl…

  3. comment
    Comment #42950006

    Google SafetyNet is basically swiss cheese with lots of bypass solutions for custom ROMs. A TPM may only attest that it has received an expected set of measurements (hashes). As lo…

  4. comment
    Comment #42948501

    Widevine L1 requires a trusted execution environment for decrypting video and only showing it on HDCP monitors. It's built on top of Intel PAVP, AMD secure display, or ARM TrustZon…

  5. comment
    Comment #42947838

    > Does TPM support/requirements actually have any meaningful impact on a home user? Disk encryption, Windows Hello and PIN bruteforce prevention. I have no love Microsoft and avoid…

  6. comment
    Comment #42947736

    There are none. It's so immensely frustrating to me that so many people believe that a TPM is a DRM device. I'm sure Richard Stallman's Treacherous Computing article played a big p…

  7. story
  8. comment
    Comment #40465626

    I think if the process was made easy, it would save quite a bit more than 1% of these devices from the landfill, assuming you have enough power users to build a community. Plenty o…

  9. comment
    Comment #40465346

    I firmly believe that permanent key fusing to lock bootloaders should be outlawed. At the very least the keys (and schematics) should be released once the device reaches EOL. Other…

  10. comment
    Comment #40343450

    Yeah, that's not something anyone should be saying to random people online.

  11. comment
    Comment #40249811

    Do Android Auto and VoLTE / VoWiFi work on Graphene these days? I also remember Google Maps and Uber being extremely problematic

  12. comment
    Comment #39756682

    Application Processor, i.e. the main processor

  13. comment
    Comment #39026296

    I would like to be able to ensure that only boot loaders signed with my private key can be executed. Secure Boot serves that purpose well, can I do that with your approach? Likewis…

  14. comment
    Comment #39026269

    Rust won't magically fix every vulnerability and someone would have to pay a team of engineers to rewrite everything.

  15. comment
    Comment #39026196

    Some piece of code has to configure the CPU, initialize memory before you can even think about loading an OS...

  16. comment
    Comment #38998690

    All Zen 1 CPUs and newer have the PSP / ASP security processor which is ARM based and runs before the x86 cores are released from reset. This applies to all Zen models, not just th…

  17. comment
    Comment #38830835

    I think ChromeOS Freon was close to what you're describing, but they ended up switching to Wayland at some point

  18. story
  19. comment
    Comment #38155380

    Dropping a link to a project attempting to create a fully open source TPM: https://twpm.dasharo.com/

  20. comment
    Comment #38155369

    In what manner specifically does a TPM not belong to the user, while a YubiKey does?

  21. comment
    Comment #38128466

    Right, but then the crawler devs will google this weird 999 code and handle it as a 429. If I wanted to mess with clients I don't like, I'd just return a random valid code.

  22. comment
    Comment #37811741

    Disappointed with Lenovo's decision to enable PSB on my T14, having previously hoped one day I'd run coreboot on it, I decided to write a checker and crowdsource a list of PSB-enab…

  23. story
  24. comment
    Comment #37737771

    Indeed, it seems that having another unlock option might be preferable. If you value your own live over the secrets, that is.

  25. comment
    Comment #37737733

    It's a matter of priorities, I guess? If you want to you can just not save the recovery password. In that case I guess they'll just beat you to death with that $5 wrench.