Brave New Trusted Boot World
0pointer.net
Brave New Trusted Boot World
1–10 of 178 posts
Re: Brave New Trusted Boot World
#2>“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated.
In what world is this a good thing? This is a one way street to an all seeing police state. I never had a problem with systemd from a technical perspective but looks like Poettering is drinking the TCB kool aid by the barrel.
Re: Brave New Trusted Boot World
#3Re: Brave New Trusted Boot World
#4>System ready for easy remote attestation, to prove validity of booted OS, configuration and local identity >“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated. In what world is this a…
This (especially) includes the machine's firmware and kernel because that's where malware could effectively hide itself from countermeasures deployed on the machines directly.
If I can then also make sure that the various admin interfaces in our network can only be used by machines in a known-good state, I would sleep ever so much better knowing that the various hacks we have seen happening to 1Password, Uber, etc this year cannot happen on my network.
I would even say that this is helpful for my users because they will never risk being "the one who let the ransomware in".
This isn't about your own private machine. This is about corporation-owned machines in an enterprise network and as we see with nearly biweekly news articles about large-scale ransomware attacks, private data leaks and compromised employee machines, I would argue that the currently employed solutions clearly don't work.
Re: Brave New Trusted Boot World
#5There is something ironic about the FOSS projects these days embracing attestation rather than standing up for user rights by vehemently rejecting it.
Re: Brave New Trusted Boot World
#6>System ready for easy remote attestation, to prove validity of booted OS, configuration and local identity >“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated. In what world is this a…
Don´t you love our modern leaders?
Re: Brave New Trusted Boot World
#7There is something ironic about the FOSS projects these days embracing attestation rather than standing up for user rights by vehemently rejecting it.
Re: Brave New Trusted Boot World
#8There is something ironic about the FOSS projects these days embracing attestation rather than standing up for user rights by vehemently rejecting it.
Re: Brave New Trusted Boot World
#9>System ready for easy remote attestation, to prove validity of booted OS, configuration and local identity >“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated. In what world is this a…
Secureboot is a scary technology but as long as we can disable it and provide our own keys I don't see the problem. And if we lose these abilities than I'm certain it won't be Poettering or systemd to blame
Re: Brave New Trusted Boot World
#10>System ready for easy remote attestation, to prove validity of booted OS, configuration and local identity >“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated. In what world is this a…
If I was responsible for a large enough fleet of machines in my enterprise and I would have to deal with 100s of users of various technical knowledge while at the same time being blamed for the eventual ransomware attack, I would absolutely want to make sure that the only software that gets to run is the one I want running. This (especially) includes the machine's firmware and kernel because that's where malware coul…
The fundamental issue is that you can't have one without the other, and that's bothering me. It's not like only corporate grade laptops come with TPMs now (like they did in the past).
Safetynet on my phone is the same thing and it's very much "about my own private machine". Seeing the reactions and the lack thereof about these developments makes me think this will end terribly.