I'm not sure how much extra "security" you're really getting out of staying strictly within ChromeOS. Yes, Secure Boot is disabled. However, the ChromeOS partition is still encrypted, and you can manually encrypt any of your crouton chroot environments, so someone looking at the thing still wouldn't be able to peek into the contents. If you're asked, "Why is this in Developer Mode?", you can answer, "I'm a developer.…
How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
101–110 of 179 posts
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#102Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#103I'm not sure how much extra "security" you're really getting out of staying strictly within ChromeOS. Yes, Secure Boot is disabled. However, the ChromeOS partition is still encrypted, and you can manually encrypt any of your crouton chroot environments, so someone looking at the thing still wouldn't be able to peek into the contents. If you're asked, "Why is this in Developer Mode?", you can answer, "I'm a developer.…
So an inadvertent wipe is really just an inconvenience of 30-60 minutes, and if it's a border patrol or TSA agent you can then have fun acting all indignant at how they broke your device and you lost so much work and your boss is gonna kill you and you want to talk to their supervisor right now.
The lack of hardware security is a consideration, but frankly if your device is handled by a malicious actor outside of your control, you're kinda screwed anyways.
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#104As a side point about Termux, Android 7 finally stopped hijacking the control+space combination, so you can use emacs efficiently. Termux is really useful, giving you an almost complete linux environment in Android phones and tablets. You can install it via Google Play, no need for root or any modification to your device. Add an external keyboard and you can work on the go.
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#105I'm not sure how much extra "security" you're really getting out of staying strictly within ChromeOS. Yes, Secure Boot is disabled. However, the ChromeOS partition is still encrypted, and you can manually encrypt any of your crouton chroot environments, so someone looking at the thing still wouldn't be able to peek into the contents. If you're asked, "Why is this in Developer Mode?", you can answer, "I'm a developer.…
I think I am misunderstanding you, but isn't paragraph 2 an argument for staying in normal Chrome OS (as this article suggests) instead of enabling developer mode?
I mentioned above that I think Caret is a great Sublime clone, but I also like having the real SublimeText, with its awesome add-on packages, Git integration, etc. The article's recommendation that you must stick with Android-enabled Chromebooks limits your options, and the only reason the recommendation exists is that he needs some way of getting access to the developer tools--gcc, etc. A crouton chroot gets you there the same way, and I'd argue it's better since the programs are running natively rather than through an emulated Android layer.
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#106One of the BIGGEST drawbacks using a Chromebook with 11.6 inch screen that nobody here talks about yet, is the grainy and crappy 1366 x 768 screen resolution! I've been a long time Macs guy anything inferior than RetinaDisplay will considerably straining my eyes before I am used to it. Dell XPS 13 included.
If you're going to compare to a Mac, it's better to look at the higher end Chromebooks like the Pixel 2, HP Chromebook 13, and Samsung Chromebook Pro. They all have screens with pixel density and quality that's on par with the 15" MacBook Pro I have.
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#107Yubikeys tend to wear out your USB ports after a bit I found, at least on my X201 and the X61 that preceded it.
Any port used frequently will wear out - they have limited life spans due to the moving parts. I see it with my external display ports pretty frequently. One potential solution is a USB hub, or even a USB extension cable you keep plugged in.
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#108Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#109Earlier quoted context omitted.
> Edit; I've been using a de-chromed chromebook for over a year […] Ok, but as the article states, they did not de-ChromeOS it because they wanted TPM and Verified Boot and FIDO-certified U2F security key so that they didn't defeat the whole purpose of buying a Chromebook. FTA: “As far as Debian/Ubuntu (and crouton), that's fine as far as it goes, but then you don't end up with a Chromebook, just a cheap mini-noteboo…
You can have verified boot, and use the TPM and the U2F security key without the chrome os on a chromebook.
We all know you can put Chromebooks into dev mode and load Ubuntu, in fact I thought it was necessary to get the most out of Chromebooks. If it turns out that Chromebooks can make decent dev environments without nuking and installing Ubuntu or whatever and if they can run Android apps then Chromebook suddenly become a very interesting value proposition.