Live data from Hacker News

The Framework Laptop Chromebook Edition

frame.work

431–440 of 476 posts

Re: The Framework Laptop Chromebook Edition

#431

Earlier quoted context omitted.

(Disclaimer: I work on ChromeOS at Google) I would let anyone, even a total stranger, use my Chromebook in guest mode without a second thought (as long as I am reasonably sure they won’t steal it, break it, or disassemble it).

(Disclaimer: I also work at Google but not directly on ChromeOS.) Exactly. I would never let my (non-tech savvy) grandparents near a Linux machine without supervision, but I wouldn't hesitate to let them near a Chromebook in guest mode. Linux is quite secure in the hands of an experienced user. ChromeOS is secure in the hands of anyone who's not state sponsored attacker-adjacent.

What do you think your technically inept family could actually do to your Linux system?

The permission model is such that the most damage they should be able to do, is to an account you've provided to them

Or are we assuming they get sudo and unlimited time, like the typewriter thing?

I'd be more worried handing it over to a experienced person who's familiar with rd.break, assuming the filesystem isn't encrypted

I specifically give family members Linux so I don't have to go clean hundreds of toolbars and the like, as I've had to with their Windows boxen

Re: The Framework Laptop Chromebook Edition

#433

Earlier quoted context omitted.

I'm a fan of Linux and a fan of ChromeOS. but are the user experience and security better on ChromeOS than Linux? It's a bit simpler than linux but I'd say Linux is a close second.

(Disclaimer: I work on ChromeOS at Google) I would let anyone, even a total stranger, use my Chromebook in guest mode without a second thought (as long as I am reasonably sure they won’t steal it, break it, or disassemble it).

I guess in practice this doesn't come up often. but it's a powerful testament to your confidence in ChromeOS' security. You are implying that you don't feel the same way about a Linux user guest login. But why? What additional security measures are present in ChromeOS that are missing from popular Linux distros?

I don't doubt the features are there, I'm genuinely curious what they are.

Re: The Framework Laptop Chromebook Edition

#434

Earlier quoted context omitted.

(Disclaimer: I work on ChromeOS at Google) I would let anyone, even a total stranger, use my Chromebook in guest mode without a second thought (as long as I am reasonably sure they won’t steal it, break it, or disassemble it).

Would you be at all concerned about the security and privacy of your guest user’s data, given your employer’s propensity for slurping up and storing whatever user data they can get their hands on? What if your guest user was searching for terms related to abortion in a US state where that procedure is (or will shortly be) illegal? What if they’re doing that and you happen to be physically near a provider of abortions…

The host operating system does not give me more or less confidence in the security of a guest user’s web browsing data.

Re: The Framework Laptop Chromebook Edition

#435

Earlier quoted context omitted.

(Disclaimer: I also work at Google but not directly on ChromeOS.) Exactly. I would never let my (non-tech savvy) grandparents near a Linux machine without supervision, but I wouldn't hesitate to let them near a Chromebook in guest mode. Linux is quite secure in the hands of an experienced user. ChromeOS is secure in the hands of anyone who's not state sponsored attacker-adjacent.

It's not quite the same as "guest mode" on ChromeOS, but I make user accounts (no sudo) for non-technical family members and let them use my machines unsupervised. What are you worried about here? Should I be worried?

It depends on how much you trust your family members and whether you worry about non-root malware.

Looking at my Linux machine, I notice that the default permission for home directories is 755. If I don’t think to tweak that, then I’m potentially exposing a lot of sensitive data to other users (and potentially the programs they run).

I’m a proficient Linux user but not an expert, and I’m racking my brains to think of what else might be exposed to other users on my machine.

Re: The Framework Laptop Chromebook Edition

#436

Earlier quoted context omitted.

(Disclaimer: I work on ChromeOS at Google) I would let anyone, even a total stranger, use my Chromebook in guest mode without a second thought (as long as I am reasonably sure they won’t steal it, break it, or disassemble it).

I guess in practice this doesn't come up often. but it's a powerful testament to your confidence in ChromeOS' security. You are implying that you don't feel the same way about a Linux user guest login. But why? What additional security measures are present in ChromeOS that are missing from popular Linux distros? I don't doubt the features are there, I'm genuinely curious what they are.

You can harden and configure a Linux system to have many of the ChromeOS security features, but ChromeOS has all of these enabled by default:

- All user data is encrypted at the login level. A guest user cannot access any other users’ data. Whereas in Ubuntu, for example, home directories have 755 permissions.

- The Linux userspace in ChromeOS is actually running on KVM, so ChromeOS itself is insulated from user-installed malware.

- Verified boot is huge. It is theoretically impossible for a modification to system-level software to survive a reboot. An attacker would have to modify the hardware too. And even if someone stole your Chromebook and modified the hardware to run malware, your data is still encrypted.

If you are interested, a more thorough explanation can be found here: https://chromium.googlesource.com/chromiumos/docs/+/HEAD/sec...

Re: The Framework Laptop Chromebook Edition

#437
post #2

I'm happy to answer questions anyone has on this product!

With Coreboot and the ChromeOS Linux kernel running well on the device, how much would it take to release a Framework Laptop Linux Edition based on the Chromebook mainboard, but with a standard keyboard and somewhat optimized for a pre-installed Linux distribution?

I would imagine that regular Linux won't do as well as ChromeOS in terms of battery life, but perhaps still considerably better than the Windows mainboard+firmware.

Re: The Framework Laptop Chromebook Edition

#438
post #7
post #3

Earlier quoted context omitted.

What’s the difference from original?

ChromeOS! Specifically, the Mainboard is custom-designed for ChromeOS. This means it uses coreboot instead of a proprietary BIOS and has Google's Titan C security chip. There are some other smaller differences. To keep the cost down, the top cover is aluminum-formed instead of CNCed, for compatibility reasons we weren't able to bring our fingerprint module in, and we were able to improve both audio quality and speake…

FYI — I emailed your support team and was told the Chromebook did have a fingerprint reader. Which surprised me because I hadn't see it on the product page at https://frame.work/products/laptop-chromebook-12-gen-intel

They pointed me to this /gb/en/ url, which has the same chromebook slug but seems to just describe the regular 12th gen laptop: https://frame.work/gb/en/laptop-chromebook-12-gen-intel

So to be clear, no fingerprint reader for the Chromebook? Any chance of adding that in the future?

Re: The Framework Laptop Chromebook Edition

#439
post #381

Earlier quoted context omitted.

low-tech users don't care much for their privacy in my experiences. This may be due partially due to the lack of understanding, but also due to cultural differences different from the average hn user. The time needed to teach them how to use complicated security systems just isn't worth it for them most of the time. People have different priorities. Most people just want to use their computers as a utility or for pla…

If an oven leaked a lot of pm2.5 or Carbon Monoxide and it happened to still be legal, it would still be an ethical obligation for someone that is aware of these issues to recommend against that oven even if someone just wants the cheap/easy option and does not comprehend the risks. Those that can comprehend significant technical risks are obligated to recommend a low-risk strategy until people have enough relevant u…

I agree with most of what you said. I think privacy is important and it is important to educate people on these issues. I just think that say a grocery store worker that just wants to get the bills paid for next month and enjoy life a little has a different set of priorities than a tech worker making > 60,000 USD. There are more people like that in the United States than tech workers.

Re: The Framework Laptop Chromebook Edition

#440

Earlier quoted context omitted.

It's not quite the same as "guest mode" on ChromeOS, but I make user accounts (no sudo) for non-technical family members and let them use my machines unsupervised. What are you worried about here? Should I be worried?

It depends on how much you trust your family members and whether you worry about non-root malware. Looking at my Linux machine, I notice that the default permission for home directories is 755. If I don’t think to tweak that, then I’m potentially exposing a lot of sensitive data to other users (and potentially the programs they run). I’m a proficient Linux user but not an expert, and I’m racking my brains to think of…

I'm similarly racking my brain, and I came to the same finding.

755 permissions on the home directory lets others see what you have, which isn't great.

The good and bad news is, permissions on the files matter too.

SSH (private) keys for example categorically won't work outside of 600 permissions, meaning nobody else can read your private key - without escalating privileges

Now, if you go defining auth secrets in your shell profile (which is world-readable by default), probably something to reconsider.

Restricting umask is a good protection for this, for what it's worth. You can make it so that newly created files/directories are not accessible to the world

Post reply on HN