I'm not sure how much extra "security" you're really getting out of staying strictly within ChromeOS. Yes, Secure Boot is disabled. However, the ChromeOS partition is still encrypted, and you can manually encrypt any of your crouton chroot environments, so someone looking at the thing still wouldn't be able to peek into the contents. If you're asked, "Why is this in Developer Mode?", you can answer, "I'm a developer.…
How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
131–140 of 179 posts
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#132Earlier quoted context omitted.
Depends on the provider. From some quick Googling Lastpass at least requires email verification before disabling Yubikey support. https://lastpass.com/support.php?cmd=showfaq&id=2546 Even for providers that do provide seamless failover, the inevitable "we see you requested an account recovery" email would serve as useful canary to know you're being targeted.
> Depends on the provider That was the whole point of my comment. It is up to the vendor and vendors do a horrible job. > the inevitable "we see you requested an account recovery" email would serve as useful canary There is nothing useful here. They are allowing you to bypass a secure key with a dumb email confirmation. Your idea of a 'useful canary' is great; until you get rooted at 5 AM on a Monday morning and that…
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#133Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#134Earlier quoted context omitted.
It might be better to give your data to someone who has to tell you how they're spying on you, than to somebody who legally shouldn't be able to but does so anyway.
It's a false alternative. Encrypt your hard drive with a key on a thumb drive on your person. Problem solved: nobody can read your hard drive unless they physically get your key as well.
I hear ya. But he was fairly particularly and upfront about his scope.
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#135What's the alternative solution for a cloud/remote based factory wipe, travel and restore? Is there anything on Linux that offers the same quality of user experience without being hampered by chromeOS and dealing with Google/a 3rd party?
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#136Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#137What's the alternative solution for a cloud/remote based factory wipe, travel and restore? Is there anything on Linux that offers the same quality of user experience without being hampered by chromeOS and dealing with Google/a 3rd party?
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#138Earlier quoted context omitted.
a) because he was impressed by the ChromeOS security model? b) because he got cloud sync/restore seamlessly out of the box? c) because thats twice as expensive for a used item? I get that people have nebulous concerns about Google's privacy policy, but he mentions specifically at the beginning of the article that he was interested in the ChromeOS security model. There are very few systems that have a model that match…
Those reasons are understandable. I guess I'm confused why a software developer needs to save $200 on a travel device with I would love it if Android apps could somehow replicate the dev tools of a standard full-featured OS one day. I'm definitely a fan of ChromeOS.
2) I think he was willing to do so because he knew not everyone has money to burn.
3) At the price point he settled on he could treat a loss as a burner. And $200 and you might not be as forgiving about a loss.
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#139What's the alternative solution for a cloud/remote based factory wipe, travel and restore? Is there anything on Linux that offers the same quality of user experience without being hampered by chromeOS and dealing with Google/a 3rd party?
Get two yubikeys. Set up LUKS full disk encryption the usual way on Ubuntu. Install yubikey-luks and yubikey-personalization-gui. Set up yubikeys for HMAC challenge response on a free slot. Enroll both keys using yubikey luks. Clear slot 0, leaving you with an encrypted brick unless you have one of two yubikeys. Mail one key to your destination. Leave the other key at home. Travel, pickup key, use it to access device…
1. If I change my plans I have to go back home or go to my original destination to pick up a key to decrypt 2. I might get there before my yubikey arrives 3. An adversary might look at my machine, and know there is data on there (in the chrome book case it just looks like a new machine), they could then detain me indefinitely or travel with me to my destination and force me to decrypt
So it's not practical for casual use IMO
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#140I'm not sure how much extra "security" you're really getting out of staying strictly within ChromeOS. Yes, Secure Boot is disabled. However, the ChromeOS partition is still encrypted, and you can manually encrypt any of your crouton chroot environments, so someone looking at the thing still wouldn't be able to peek into the contents. If you're asked, "Why is this in Developer Mode?", you can answer, "I'm a developer.…
As someone who has an on-off interest in ChromeOS but with little to no knowledge about it, does vim/neovim work? I found some vim version on the chrome web store but it is last updated on 2014 and pinned to 7.4 which was a bit disappointing.
Yes, they work.
No, they don't capture shortcuts like 'ctrl+W' which are handled by ChromeOS.