To use with a modified Linux kernel that emulates a bog standard Thinkpad uefi environment of course.
EDIT: I forgot to phrase this as a question - besides missing a QubesOS or KickSecure on top, is this a decent plan for airgapped stuff?
31–40 of 125 posts
To use with a modified Linux kernel that emulates a bog standard Thinkpad uefi environment of course.
EDIT: I forgot to phrase this as a question - besides missing a QubesOS or KickSecure on top, is this a decent plan for airgapped stuff?
Hah, this reminds of a security researcher a few years ago that was reporting malware that he couldn't research without infecting his other machines. I'm fuzzy on the details, but everyone wrote him off as a paranoid delusional and the incident was quickly swept under the rug. Makes me wonder if he found some sophisticated state sponsored stuff and got smeared to hush it up. I mean realistically, we'd be naive to not…
That's why things like the Pluton processor and TPMs are useful. (A rain of downvotes falls on me) Seriously, even good old BIOS is susceptible to rootkits, there has been tons of them. So no crying over UEFI please. We need a fully signed and auditable chain of trust for booting OSes. Of course all this crap needs to be open source but it needs to be locked down to prevent not trusted binaries as much as possible. A…
> Seriously, even good old BIOS is susceptible to rootkits, there has been tons of them. Were there? I couldn't find anything, but then again Google is garbage nowadays if you want to find older stuff. To my understanding, the limitations of the old BIOS world would've made it much harder to hack on it other than maybe enabling hidden menus. The UEFI world is so much larger, more powerful and already offers plenty of…
Earlier quoted context omitted.
The problem with pluton is not the tech. It's that: - it's proprietary - it's controlled by entities that have a terrible track record - it's going to be, as usual, forced upon everybody without consent
I have argued the same as you, it needs to be open source to fix the first two points. For the third one, nobody is forcing you to buy a specific product, but yes, it will be hard to avoid. But like for vaccines, individual consent is at odds with the greater good. Society needs computing that it can trust. Maybe the solution is a healthier hobbyist market where you can buy "use at your own risk" unlocked computers?…
There's no reason to think a large, opaque computing base that's been forced into the market by a monopoly power is trustworthy. I'd argue that "boot sector tampering with physical access" is pretty low on the list of computer-related real-world attacks against society; it's certainly lower than zero-days caused by implementation errors in baroque computer software / hardware.
Also, suggesting you can avoid having a computer (or phone) at this point is ludicrous. It's like suggesting you can avoid using credit cards and cash. Some would argue it is actually easier to give up living under a roof than to give up owning a cell phone (and make exactly that tradeoff).
That's why things like the Pluton processor and TPMs are useful. (A rain of downvotes falls on me) Seriously, even good old BIOS is susceptible to rootkits, there has been tons of them. So no crying over UEFI please. We need a fully signed and auditable chain of trust for booting OSes. Of course all this crap needs to be open source but it needs to be locked down to prevent not trusted binaries as much as possible. A…
> The most striking aspect of this report is that this UEFI implant seems to have been used in the wild since the end of 2016 – long before UEFI attacks started being publicly described. This discovery begs a final question: if this is what the attackers were using back then, what are they using today? I always marvel at the ingenuity and technical complexity of these kinds of attacks, but this is also something that…
Earlier quoted context omitted.
I have argued the same as you, it needs to be open source to fix the first two points. For the third one, nobody is forcing you to buy a specific product, but yes, it will be hard to avoid. But like for vaccines, individual consent is at odds with the greater good. Society needs computing that it can trust. Maybe the solution is a healthier hobbyist market where you can buy "use at your own risk" unlocked computers?…
This would be comparable to vaccines if Bill Gates had actually hidden tracker/kill-switch chips in each dose... There's no reason to think a large, opaque computing base that's been forced into the market by a monopoly power is trustworthy. I'd argue that "boot sector tampering with physical access" is pretty low on the list of computer-related real-world attacks against society; it's certainly lower than zero-days…
My mother does not have an Internet connection. Or a computer. Or a cell phone.
She definitely prefers to live under a roof. She's just not interested in any of the above.
My hopes of large volume fully open source systems died when I learned that beefy RISC V boards will ship with UEFI.