While it would be great to liberate x86, more than 4 billion people in the world use mobile phones, and phones are beyond saving. x86 is in very healthy shape compared to the clusterfuck that is the smartphone industry. If you think that coreboot is a fringe project, you need to head over to replicant or neo900 to see what the fringe actually is.
Uncorrectable freedom and security issues on x86 platforms (2016)
101–110 of 141 posts
Re: Uncorrectable freedom and security issues on x86 platforms (2016)
#102... I confess I'm very frustrated reading about how trusted computing modules hurt the cause of FOSS but no alternatives to actually try and carry out cryptography to execute trusted code. Inevitably the complaint is, "Well if they have physical access you're screwed anyways." And I just don't understand how anyone can maintain that farce when the last year has shown that it's a genuine challenge even for the US FBI…
The FBI issue wasn't a technical issue. When they gave up on grandstanding, the phone was cracked in hours.
Re: Uncorrectable freedom and security issues on x86 platforms (2016)
#103Earlier quoted context omitted.
I feel like you danced around the central point of my post: there is no suggestions for how to secure and harden devices without refining these trusted computing techniques. We need to harden these devices. Your argument is no one can be trusted to make them. But my argument is that if you believe that then you know you can't trust anyone to make anything one way or the other. Surely rather than botch the whole thing…
> there is no suggestions for how to secure and harden devices without refining these trusted computing techniques. We need to harden these devices. Because the thing you are asking for is not possible. You have a bad premise: > And I just don't understand how anyone can maintain that farce when the last year has shown that it's a genuine challenge even for the US FBI to unlock a mobile device without the owners say-…
They bought a hack from another company for an old model of phone. If the case had been involving the latest model handset, the vendor claimed they had not yet (but were confident they would) hack it.
> The problem is, if someone has physical access to your device and can compromise your firmware, they can record your passphrase the next time you unlock the device, and then they don't need to break the encryption.
And if the device is tamper-resistant? I had this same conversation with a person who hated Yubikey. Nearly exactly the same. It made even less sense, because the entire point of the Yubikey is to be tamper proof.
> The only answer to these attacks is physical security. Secure boot does nothing.
I think maybe what I object to most is that essentially the only attacks considered in this discourse are attacks directly by nation-states at scale. Not only is it clear that handsets and self-built computers are subject to these (at scale), but it's doubly not sure that if you used a TPM then you wouldn't be exposed to attacks against TPM-backdoored devices since your information in an online world is stored on commodity clouds that probably DO have that hardware and if an attack exists, it'll certainly be able to ignore FDE.
Even if we ignore that, TPM mitigates real attacks we see in the real world, and increases the difficulty of those attacks. Average consumers are a case that should be considered in the discourse.
Most people can't effectively harden themselves against nation-state level attacks (if only because incarceration and interrogation exist and even physical security won't stop them), but nation-state level attacks involving a conspiracy amongst manufacturers and the NSA is the justification used to discredit the use of TPMs.
And for the dubious benefit of saying, "Well I have a spec and presumably this board is fully defined by this spec." Of course, truly verifying the board has no back doors is not made substantially easier by the absence of a TPM. So I have trouble believing that this is not an argument among different factions who want final say on a wide variety of consumer hardware.
Re: Uncorrectable freedom and security issues on x86 platforms (2016)
#104Earlier quoted context omitted.
Thanks for the detailed answer. In regards to: >" Most implementations only allow 1 PK, and that PK is Microsoft's." Isn't this a bit monopolistic and coercive though? "If you want the Microsoft Hologram on your product the PK has to be has to be Microsoft and there can only be one PK." I can't believe this doesn't violate some type of anti-trust laws.
How so? The OEMs want to make hardware that runs Windows. Microsoft provides a specification[0] and certification suites[1] that defines what "Windows-compatible" means, which OEMs then follow. Nothing coercive about that. There is no open standard that defines what a PC is. Linux and other operating systems are piggybacking on the Windows PC standard. If they want OEMs to manufacture hardware to their standards, the…
I disagree. I think the OEMs want to make hardware that consumer buy. I don't think they care one bit what OS consumers run on top of their hardware. In fact I would imagine OEMS would prefer to bring their products to market without consulting Microsoft at all.
It's coercive in the sense the the secure execution is predicated on there only being one PK and the OEMs have to knuckle under to MS just to be considered a "potential" machine that Microsoft allows to run Windows.
>"Linux and other operating systems are piggybacking on the Windows PC standard."
What exactly is the "Window PC Standard"? I have never heard this term before. Linux didn't piggy back on Windows anything. Maybe you mean X86? X86 predates Windows.
Re: Uncorrectable freedom and security issues on x86 platforms (2016)
#105While it would be great to liberate x86, more than 4 billion people in the world use mobile phones, and phones are beyond saving. x86 is in very healthy shape compared to the clusterfuck that is the smartphone industry. If you think that coreboot is a fringe project, you need to head over to replicant or neo900 to see what the fringe actually is.
Well, then you can go deeper and check out baseband firmware liberation project - OsmocomBB [1], since baseband firmware in a far worse shape than applications firmware (and TrustZone firmware) in smartphone industry. [1] https://osmocom.org/projects/baseband
Re: Uncorrectable freedom and security issues on x86 platforms (2016)
#106Earlier quoted context omitted.
NSA 100% . Some time around 10 years ago governments decided the internet was too "dangerous" to be free. Arab spring cemented that into their minds, and now a bastion of free thought has become the worlds biggest spying apparatus.
Try using Intel ME. Than come back and tell us that's a tool for mass surveillance. If you think there's a evil NSA front for this type of stuff -- its Absolute Software. Their bits have been embedded in most BIOS packages since the 90s, and nobody has heard of them.
You can wipe, encrypt, lock, view & kill processes, retrieve any file and view every file on machine, and view hardware & software status and licensing. It also incorporates a bunch of other features, but those are what scare me most.
This is only made worse by the fact that it is readily exploitable: https://threatpost.com/millions-of-pcs-affected-by-mysteriou...
Re: Uncorrectable freedom and security issues on x86 platforms (2016)
#107I was struck by the following passage: >including Secure Boot, which even now requires FOSS users to purchase a license from Microsoft to boot FOSS on affected machines that lack an appropriate Secure Boot override." Can someone explain this to me, would this be for instance be Lenovo laptops making a deal with Microsoft since Windows is the default OS installed on these laptops? Is Microsoft mandating all OEMs/hardw…
Is Microsoft mandating all OEMs/hardware vendors to configure secure boot with a MS signing key? Basically yes; it's required to get the Windows sticker. I haven't heard that MS charges money to sign bootloaders, though.
If you look at the UEFI requirements for Windows 10[1], specifically clauses 19 and 20, it says for non-ARM systems the user MUST be able to put Secure Boot into Custom signature-checking mode.
[1] https://msdn.microsoft.com/windows/hardware/commercialize/de...
Re: Uncorrectable freedom and security issues on x86 platforms (2016)
#108Earlier quoted context omitted.
Is Microsoft mandating all OEMs/hardware vendors to configure secure boot with a MS signing key? Basically yes; it's required to get the Windows sticker. I haven't heard that MS charges money to sign bootloaders, though.
I believe that the Windows 10 logo requirements are exactly the opposite of that. If you look at the UEFI requirements for Windows 10[1], specifically clauses 19 and 20, it says for non-ARM systems the user MUST be able to put Secure Boot into Custom signature-checking mode. [1] https://msdn.microsoft.com/windows/hardware/commercialize/de...
Re: Uncorrectable freedom and security issues on x86 platforms (2016)
#109Re: Uncorrectable freedom and security issues on x86 platforms (2016)
#110Earlier quoted context omitted.
Well, then you can go deeper and check out baseband firmware liberation project - OsmocomBB [1], since baseband firmware in a far worse shape than applications firmware (and TrustZone firmware) in smartphone industry. [1] https://osmocom.org/projects/baseband
I don't think baseband can ever be truly free because of regulatory issues. The only realistic way of containing it would be through isolation.