Live data from Hacker News

Brave New Trusted Boot World

0pointer.net

91–100 of 178 posts

Re: Brave New Trusted Boot World

#91

Earlier quoted context omitted.

It's not a "theoretical DRM use case" if you stop thinking in terms of movie piracy for a moment, and consider what's happening with banking apps on mobile platforms. Thanks to remote attestation, the custom ROM scene for Android is pretty much dead now, because there's little point of customizing the OS when it automatically makes important services no longer accessible from the phone.

That's the entire point. Your bank doesn't want you to run their software on your potentially vulnerable hardware.

And why should the bank's opinion be relevant here?

Re: Brave New Trusted Boot World

#92
post #2

>System ready for easy remote attestation, to prove validity of booted OS, configuration and local identity >“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated. In what world is this a…

Many folks prioritize preventing practical in-the-wild blue pill attacks over preventing the theoretical DRM use case.

I would argue the blue pill attacks _are_ theoretical for the majority of users, while DRM overreach are at least a daily occurrence.

The complexity and bugs of these "protections" is likely to cause more actual security issues AND headaches to average users than the "evil maid" scenario these blog posts like to speak of.

Re: Brave New Trusted Boot World

#93
post #76

"Considered attack scenarios and considerations: Evil Maid: [.. ] physical access to a storage device should [not] enable an attacker to read the user’s plaintext data [..]. [or] allow undetected modification/backdooring of user data or OS (integrity), or exfiltration of secrets." Am I misunderstanding, or is the the only attack scenario listed? Seems like a lot of work, complexity and potential problems of all sort…

> Seems like a lot of work, complexity and potential problems of all sort to fix.. something quite minor?

Probably because the main goal isn't actually solving that problem. That's just the excuse used to let the trojan horse in and convince people to hand complete control of their devices over to corporations.

Re: Brave New Trusted Boot World

#94
post #5

There is something ironic about the FOSS projects these days embracing attestation rather than standing up for user rights by vehemently rejecting it.

If you were responsible for the security of your enterprise network, would you vehemently fight for your user's rights to run the ransomware executable they just get sent over email?

This may come as a shock to you, but computers exist outside of a corporate context.

Re: Brave New Trusted Boot World

#95
post #2

>System ready for easy remote attestation, to prove validity of booted OS, configuration and local identity >“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated. In what world is this a…

This is where computing as a whole is headed because it's the ONLY way to provide defense in depth against cyberattacks. Signed code path from first boot to user space code. Remote attestation because you can NEVER trust the client. Microsoft and especially Apple are already doing this. Linux needs an answer, and "no, it's too user hostile" is NOT a valid answer; it will just make Linux an untenable security risk.

It's like I keep saying, the Wild West 90s internet is long gone and nothing will bring it back. This is where things are headed, because the risks of the status quo are too great. Suck it up and get on with your life.

Re: Brave New Trusted Boot World

#96
post #75

Earlier quoted context omitted.

I keep hearing that Microsoft is making things "harder", but I've yet to see any evidence that this is true. All I can see is that Microsoft mandate that laptop hardware sold with Windows installed have secure boot capability and that the MS-signing keys are shipped in the TPM. This has been true for, what, over 10 years? How are they making things harder?

There are quite a few instances[1] where adding your own signing keys bricks the device. [1] https://wiki.archlinux.org/title/Unified_Extensible_Firmware...

Huh, wasn't aware of that. Reading through, it looks like this is just talking about Microsoft "Secured-core" hardware, which seems to be hardware specifically marketed to provide a Microsoft-certified boot chain.

I'm not sure that's the same thing as Microsoft making it harder in general for people to bring and use their own keys (or just turn it off altogether).

Re: Brave New Trusted Boot World

#97

As somone who never really viewed systemd as a problem I'm starting to think the systemd "haters" were actually right, at least somewhat... Viewing Poettering as some kind malicious entity undermining projects sounds like a conspiracy theory. But now with him working for Microsoft his actions do look like a lot like the "embrace, extend, and extinguish" pattern to me. Yes, yes "Microsoft And now I am supposed to chee…

Poettering's work is a love letter to windows xp.

Re: Brave New Trusted Boot World

#98

There is something ironic about the FOSS projects these days embracing attestation rather than standing up for user rights by vehemently rejecting it.

It's called "defense in depth". A signed, attestable boot path is how you get defense in depth against malware attacks. Period. All computing is headed this way.

Re: Brave New Trusted Boot World

#99
post #95
post #2

>System ready for easy remote attestation, to prove validity of booted OS, configuration and local identity >“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated. In what world is this a…

This is where computing as a whole is headed because it's the ONLY way to provide defense in depth against cyberattacks. Signed code path from first boot to user space code. Remote attestation because you can NEVER trust the client. Microsoft and especially Apple are already doing this. Linux needs an answer, and "no, it's too user hostile" is NOT a valid answer; it will just make Linux an untenable security risk. It…

> This is where computing as a whole is headed because it's the ONLY way to provide defense in depth against cyberattacks.

Yeah, sure - in a fantasy dream world. But the real world has a bit more sophisticated cyberattackers that will find a way in. And at the same time normal and powerusers of computers will have to deal with all the total-control-state-class "security" measures.

This looks pretty the same as "think of the children" censorship.

Re: Brave New Trusted Boot World

#100

Earlier quoted context omitted.

Never attribute to malice what could be explained by... well Poettering isn't stupid really, he's clearly very talented and intelligent, but I don't think he's doing it with intent more than he doesn't really think ahead to what the system he's creating is turning into. Again, I'd say most of the developer world has this issue, just see the post a few days ago from the guy who volunteers to help elderly folks with th…

Its Foresight. Poettering is a able person, but lacks any foresight on what world he is creating.

Yeah, he's extremely satisfied by the things he accomplish, but he doesn't think (or care) about the effects of his accomplishments.
Post reply on HN