Live data from Hacker News

Brave New Trusted Boot World

0pointer.net

71–80 of 178 posts

Re: Brave New Trusted Boot World

#71
post #41

Earlier quoted context omitted.

It sounds like you're demanding to use someone's service on your own terms. I'm not sure why it's obvious that the service provider is under any obligation to entertain your desires. So.... vote with your feet and choose a bank that shares your values more closely?

> So.... vote with your feet and choose a bank that shares your values more closely? That never worked and will not work now. You can't choose something that's not being offered. EDIT: Also, > It sounds like you're demanding to use someone's service on your own terms. Well, sort of; a service agreement is a relationship, and TPM/remote attestation is a huge overreach by the corporate party. It's only fair to want to…

> That never worked and will not work now. You can't choose something that's not being offered.

Why do you think you're entitled to something that's not being offered?

I think there's a general point here about how retail banking is not really an ideal free market, because the barrier to entry is too high. If no bank is providing a set of services that fit the compromises you want to make, then either your problem is with the government (who arguably over-regulate the space) or not enough people share your values to warrant creating a banking business around it.

> Well, sort of; a service agreement is a relationship, and TPM/remote attestation is a huge overreach by the corporate party. It's only fair to want to push back on what's becoming an abusive relationship.

On the flip side, the bank has to manage a complicated series of risks, and their investors might not want to pay the mitigation costs of the risks created by allowing anyone to use their service however they like. Hence the ToS.

Re: Brave New Trusted Boot World

#72

Earlier quoted context omitted.

It's not a "theoretical DRM use case" if you stop thinking in terms of movie piracy for a moment, and consider what's happening with banking apps on mobile platforms. Thanks to remote attestation, the custom ROM scene for Android is pretty much dead now, because there's little point of customizing the OS when it automatically makes important services no longer accessible from the phone.

That's the entire point. Your bank doesn't want you to run their software on your potentially vulnerable hardware.

And soon "potentially vulnerable hardware" will be anything except AT&T devices, and we'll be back to closed networks except this time the government does not have the balls to split any of the mega-corporations.

Re: Brave New Trusted Boot World

#73
post #41

Earlier quoted context omitted.

You see this on Android, my banking app requires that it is running an OS approved by a big vendor. Their website, especially the mobile version, is getting more and more tedious to use. I want to be able to access all services with whatever client I please. Not be required to run approved software and hardware that puts them in control.

It sounds like you're demanding to use someone's service on your own terms. I'm not sure why it's obvious that the service provider is under any obligation to entertain your desires. So.... vote with your feet and choose a bank that shares your values more closely?

[deleted]

Re: Brave New Trusted Boot World

#74

I've never understood the need for all the complexity. Security should be built from the ground up from two physical ports. One is a file storage like SD card and one is a hasher/checker for the blobs that are read form that storage device. One of the blobs should be the CPU microcode. The system can be expanded with additional (tag,blobs). There. Solved every solvable use case. Okay, i lied. I do understand why ther…

Nice try :). Computing built out of cryptographically secure cons cells.

But no, this doesn't solve anything, because the root problem doesn't have anything to do with technology. The root problem is that people need to work together despite having conflicting goals and interests.

Like, e.g., the major issue with trusted computing isn't trusted computing. Everyone would like their devices to be secure against unwanted software doing bad things. The conflict is over who owns the device in the first place. I'd like to own my PC, the very one I'm writing this comment on. So does Intel, Dell, Realtek, Microsoft, my bank, every news site, half a dozen governments, and countless criminals specialized in exploiting digital technology. Whether or not TC is good for me hinges entirely on the answer to the ownership question.

As for complexity - it comes from the industry incrementally evolving technological solutions to what's a philosophical/sociological problem that doesn't have a theoretical solution yet (and might be unsolvable in general).

Re: Brave New Trusted Boot World

#75
post #39

Earlier quoted context omitted.

No-one's making you use it. Choose a distro that doesn't package it - there's plenty to choose from.

This is unfair. MS keeps making it harder and harder to run anything that is not MS-signed (TM) on Secure Boot hardware; any distro that does not bow to the whims of MS is thus likely to be relegated to obscurity or die due to lack of users capable of installing it.

I keep hearing that Microsoft is making things "harder", but I've yet to see any evidence that this is true.

All I can see is that Microsoft mandate that laptop hardware sold with Windows installed have secure boot capability and that the MS-signing keys are shipped in the TPM. This has been true for, what, over 10 years?

How are they making things harder?

Re: Brave New Trusted Boot World

#76
"Considered attack scenarios and considerations: Evil Maid: [.. ] physical access to a storage device should [not] enable an attacker to read the user’s plaintext data [..]. [or] allow undetected modification/backdooring of user data or OS (integrity), or exfiltration of secrets."

Am I misunderstanding, or is the the only attack scenario listed?

Seems like a lot of work, complexity and potential problems of all sort to fix.. something quite minor?

I mean: 1) Get a lock? 2) Will it actually stop an Evil Maid? I'm thinking of stuff like physical key-loggers, hidden cameras etc etc

edit: fixed and shortened quote

Re: Brave New Trusted Boot World

#77

As somone who never really viewed systemd as a problem I'm starting to think the systemd "haters" were actually right, at least somewhat... Viewing Poettering as some kind malicious entity undermining projects sounds like a conspiracy theory. But now with him working for Microsoft his actions do look like a lot like the "embrace, extend, and extinguish" pattern to me. Yes, yes "Microsoft And now I am supposed to chee…

Never attribute to malice what could be explained by... well Poettering isn't stupid really, he's clearly very talented and intelligent, but I don't think he's doing it with intent more than he doesn't really think ahead to what the system he's creating is turning into. Again, I'd say most of the developer world has this issue, just see the post a few days ago from the guy who volunteers to help elderly folks with their computers.

Re: Brave New Trusted Boot World

#78
post #71

Earlier quoted context omitted.

> So.... vote with your feet and choose a bank that shares your values more closely? That never worked and will not work now. You can't choose something that's not being offered. EDIT: Also, > It sounds like you're demanding to use someone's service on your own terms. Well, sort of; a service agreement is a relationship, and TPM/remote attestation is a huge overreach by the corporate party. It's only fair to want to…

> That never worked and will not work now. You can't choose something that's not being offered. Why do you think you're entitled to something that's not being offered? I think there's a general point here about how retail banking is not really an ideal free market, because the barrier to entry is too high. If no bank is providing a set of services that fit the compromises you want to make, then either your problem is…

> Why do you think you're entitled to something that's not being offered?

It's not that I feel entitled, and more that I'm required to use a bank to not starve, or at least to participate in the modern society. I'm not in this relationship by choice, I'm forced into it at metaphorical gunpoint by the economy.

And, it still means the advice to "vote with your feet" is invalid. I have no one to vote for.

> there's a general point here about how retail banking is not really an ideal free market, because the barrier to entry is too high.

There's an even more general point here, that this applies to pretty much every good and service. Not just banking, not just phones, not just computing. It applies to cars and clothes and food and housing just as well. Hence me saying that voting with your feet/wallet doesn't work in general. Mature markets end up supply-driven - vendors collectively decide what choices are available; the only way to have a vote is to become a vendor yourself, which is a long, hard and risky process.

> On the flip side, the bank has to manage a complicated series of risks, and their investors might not want to pay the mitigation costs of the risks created by allowing anyone to use their service however they like. Hence the ToS.

Sure. There are conflicting interests here. But the right answer isn't one party dictating how the entire relationship works. That's abuse.

Re: Brave New Trusted Boot World

#79
post #55
post #13

Earlier quoted context omitted.

Because it can snowball from "you may not access Widevine content on an unapproved device", which is of little significance to "you may not connect to the internet on a non government approved device" which is extremely dangerous.

It's good to know that other people can see the writing on the wall too. I've told people that this is being made possible. While it is not a guarantee that the availability of the technology will lead to the use of the technology in such a manner, the fact that it will be possible means it's just a matter of time before someone insists on doing this under the pretext of security. The saving grace is that attestation…

>The saving grace is that attestations can be forwarded

That would require you to have root on a "trusted" device so you can extract the challenge-response that proves you are indeed "trusted". Which is becoming increasingly harder with each iteration.

Re: Brave New Trusted Boot World

#80
post #67
post #56

Earlier quoted context omitted.

This number diminishes every passing year, with only debian being a bastion of sanity on the "user friendly" side of the distro spectrum.

Why do you think that is?

Because more and more software developers use hard dependencies on SystemD making alternatives difficult to maintain ?
Post reply on HN