>System ready for easy remote attestation, to prove validity of booted OS, configuration and local identity >“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated. In what world is this a…
Humanity has done a great step forward in the last 50 years or so, usually you can trust the police and governments everywhere on the planet today to always do the right thing. So why this irrational fear and this anti-state ideology? Don´t you love our modern leaders?
Brave New Trusted Boot World
11–20 of 178 posts
Re: Brave New Trusted Boot World
#12Earlier quoted context omitted.
If I was responsible for a large enough fleet of machines in my enterprise and I would have to deal with 100s of users of various technical knowledge while at the same time being blamed for the eventual ransomware attack, I would absolutely want to make sure that the only software that gets to run is the one I want running. This (especially) includes the machine's firmware and kernel because that's where malware coul…
>This isn't about your own private machine. This is about corporation-owned machines in an enterprise network and as we see with nearly biweekly news articles about large-scale ransomware attacks, private data leaks and compromised employee machines, I would argue that the currently employed solutions clearly don't work. The fundamental issue is that you can't have one without the other, and that's bothering me. It's…
AFAIK, secure boot can be disabled, both in the BIOS and in the Kernel.
In some machines that's not be the case due to contracts with Microsoft, but those already can't run Linux in the first place, so you probably won't buy them for the purpose of running Linux.
The suggestions in the original post do not change anything about this.
Re: Brave New Trusted Boot World
#13There is something ironic about the FOSS projects these days embracing attestation rather than standing up for user rights by vehemently rejecting it.
I know my reasons for feeling worried about it but I wonder why you also dislike the idea of end user operating systems making it trivial for applications to take advantage of remote attestation?
Re: Brave New Trusted Boot World
#14>System ready for easy remote attestation, to prove validity of booted OS, configuration and local identity >“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated. In what world is this a…
Re: Brave New Trusted Boot World
#15There is something ironic about the FOSS projects these days embracing attestation rather than standing up for user rights by vehemently rejecting it.
If you were responsible for the security of your enterprise network, would you vehemently fight for your user's rights to run the ransomware executable they just get sent over email?
Re: Brave New Trusted Boot World
#16Earlier quoted context omitted.
>This isn't about your own private machine. This is about corporation-owned machines in an enterprise network and as we see with nearly biweekly news articles about large-scale ransomware attacks, private data leaks and compromised employee machines, I would argue that the currently employed solutions clearly don't work. The fundamental issue is that you can't have one without the other, and that's bothering me. It's…
> you can't have one without the other, AFAIK, secure boot can be disabled, both in the BIOS and in the Kernel. In some machines that's not be the case due to contracts with Microsoft, but those already can't run Linux in the first place, so you probably won't buy them for the purpose of running Linux. The suggestions in the original post do not change anything about this.
Re: Brave New Trusted Boot World
#17>System ready for easy remote attestation, to prove validity of booted OS, configuration and local identity >“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated. In what world is this a…
If I was responsible for a large enough fleet of machines in my enterprise and I would have to deal with 100s of users of various technical knowledge while at the same time being blamed for the eventual ransomware attack, I would absolutely want to make sure that the only software that gets to run is the one I want running. This (especially) includes the machine's firmware and kernel because that's where malware coul…
Re: Brave New Trusted Boot World
#18>System ready for easy remote attestation, to prove validity of booted OS, configuration and local identity >“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated. In what world is this a…
Humanity has done a great step forward in the last 50 years or so, usually you can trust the police and governments everywhere on the planet today to always do the right thing. So why this irrational fear and this anti-state ideology? Don´t you love our modern leaders?
Re: Brave New Trusted Boot World
#19I don't trust Poetteringware. Poettering's team has a record of foisting technology on users, resulting in the need for e.g. the Devuan fork. I wish this work were being done by just about any other team than Poettering's.
Re: Brave New Trusted Boot World
#20There is something ironic about the FOSS projects these days embracing attestation rather than standing up for user rights by vehemently rejecting it.
I know my reasons for feeling worried about it but I wonder why you also dislike the idea of end user operating systems making it trivial for applications to take advantage of remote attestation?