Live data from Hacker News

Brave New Trusted Boot World

0pointer.net

111–120 of 178 posts

Re: Brave New Trusted Boot World

#111
post #62
post #44

Earlier quoted context omitted.

Systemd was designed in a way that was more tightly coupled than the alternatives and made adopting it an all-or-nothing proposition, and other projects (particularly Gnome) were also tightly coupled to it. It was absolutely foisted on people: a lot of people didn't want it but found they were nevertheless obliged to install it. The whole thing abused the goodwill of the free software community: systemd folks added s…

The tight coupling, the non-portability, all of that are technical choices, that can be debated on their own merit without the need to attribute malevolent intentions to the developers. Projects merged changes because they wanted them, not because their goodwill was abused to make them merge anything. People got systemd on their OSes because they chose OSes whose developers chose to move to systemd. It's not like Len…

> all of that are technical choices, that can be debated on their own merit without the need to attribute malevolent intentions to the developers

The ramifications of those technical choices on the software ecosystem are so well understood [0], that there is no point in discussing "their own merits" in a vacuum.

What's most relevant to my professional and waning hobbyist interests are the shape and trajectory of the software ecosystem as a whole. To talk about systemd without talking about how it's developers interact with the software ecosystem is to talk about nothing.

[0] I graduated before systemd was a glint in Pottering's eye, but we somehow still covered it in school. Not only coupling vs cohesion in the abstract, but also how various design decisions (including init system arguments of old!) interacted with the ebb and flow of unix-like OS evolution.

Re: Brave New Trusted Boot World

#112
post #75

Earlier quoted context omitted.

I keep hearing that Microsoft is making things "harder", but I've yet to see any evidence that this is true. All I can see is that Microsoft mandate that laptop hardware sold with Windows installed have secure boot capability and that the MS-signing keys are shipped in the TPM. This has been true for, what, over 10 years? How are they making things harder?

There are quite a few instances[1] where adding your own signing keys bricks the device. [1] https://wiki.archlinux.org/title/Unified_Extensible_Firmware...

As others have said, it's not a full-on brick (though I can see how it can be a pain to fix).

However, the third-party MS certificate can be signed with your own keys, as described on that same page [1].

I don't have a need for that (my PCs don't need any option ROMs), but I did sign MS's main Windows key so that I can dual boot Win11 / Arch (which MS doesn't sign) with my own key registered in the UEFI.

[1] https://wiki.archlinux.org/title/Unified_Extensible_Firmware...

Re: Brave New Trusted Boot World

#114

As somone who never really viewed systemd as a problem I'm starting to think the systemd "haters" were actually right, at least somewhat... Viewing Poettering as some kind malicious entity undermining projects sounds like a conspiracy theory. But now with him working for Microsoft his actions do look like a lot like the "embrace, extend, and extinguish" pattern to me. Yes, yes "Microsoft And now I am supposed to chee…

I fail to see how the ability to have all the bits on my unencrypted uefi partition be signed is such a doom and gloom scenario.

Having a world writeable initrd - that is an fs image with executables to be run as root before any other security settings have been enabled (etc) has always struck me as a bad idea.

Yes I'm aware that this technology, like literally every other technology ever invented (from the pointy stick all the way up), can be used for evil. That is a human problem not a "this technology exists problem"...

> ...the groundwork for the creation of an allmighty authority with the ability to "sanction" some (parts of) operating systems, but not others

"We must backdoor/ban all crypto because imagine what the criminals would do with it!"

Re: Brave New Trusted Boot World

#115
post #2

>System ready for easy remote attestation, to prove validity of booted OS, configuration and local identity >“Democratize” use of PCR policies by defining PCR register meanings, and making binding to them robust against updates, so that external projects can safely and securely bind their own data to them (or use them for remote attestation) without risking breakage whenever the OS is updated. In what world is this a…

[deleted]

Re: Brave New Trusted Boot World

#116
post #71

Earlier quoted context omitted.

> That never worked and will not work now. You can't choose something that's not being offered. Why do you think you're entitled to something that's not being offered? I think there's a general point here about how retail banking is not really an ideal free market, because the barrier to entry is too high. If no bank is providing a set of services that fit the compromises you want to make, then either your problem is…

> Why do you think you're entitled to something that's not being offered? It's not that I feel entitled, and more that I'm required to use a bank to not starve, or at least to participate in the modern society. I'm not in this relationship by choice, I'm forced into it at metaphorical gunpoint by the economy. And, it still means the advice to "vote with your feet" is invalid. I have no one to vote for. > there's a ge…

> It's not that I feel entitled, and more that I'm required to use a bank to not starve, or at least to participate in the modern society. I'm not in this relationship by choice, I'm forced into it at metaphorical gunpoint by the economy.

At my last job, it was impossible to be paid except by direct deposit into a bank account. At certain times during the past couple years, it was impossible to go into my bank to do any transacting. I feel like I should be able to have a job without needing a smart phone and an app.

Re: Brave New Trusted Boot World

#117
post #24

Earlier quoted context omitted.

> I don't trust Poetteringware. Poettering's team has a record of foisting technology on users, resulting in the need for e.g. the Devuan fork. They have been developing software, that enough people have deemed useful to include it in their distributions. Some have disagreed, and have made other choices. No one was forced to do anything, there have been no "foisting" and the "need" for Devuan is a subjective opinion.…

> There is really no need to transform purely technical arguments into personal attacks. This just discourages participating into free software development. While I agree with you in general, for some reason this particular developer tends to take decisions that have very extensive consequences and make choice extremely difficult.

I didn't make a personal attack on Poettering; my objection is to the software his team produces. And I wasn't making any technical argument; I don't know enough about TPM and secure boot to do that.

My point was a political one, I guess: this is more software that runs very deep in the system, coming from a team that has a record of producing software that is hard to opt-out of.

For PulseAudio on Debian, you have to take firm steps to ensure the package manager doesn't reinstall it. Much the same goes for systemd. I assume it will be much harder to opt-out of a secure boot released by that team. I believe that's on purpose: they could have made it easier to run without those packages, if they'd wanted to. I think it's clear that they wanted the opposite.

Re: Brave New Trusted Boot World

#118

Earlier quoted context omitted.

Some good points. Lets see what we can do here: > The problem isn’t that you can’t trust people. Good. It's always best to have an optimistic view of our fellows, that's how we build good social structures. > The problem is that people are defenceless in the face of malicious hackers So. Make then not defenceless. We arm them. With education and other tools they need to defend themselves. Digital Self Defence (Or Dig…

> Make then not defenceless. This, simply put, doesn't work in an enterprise context. I'd argue that relying on people for security doesn't work in any context, and that it's about as effective as relying on programmers to not code memory leaks, but in companies where there's people whose _only_ use of a desktop computer is at work, as is increasingly common nowadays, it's simply not possible to get half the people o…

It takes inner work to overcome a bleak view of people. It's too easy to eschew compassion and faith in fellow humans to improve themselves. I think the rehabilitation of our digital world asks us to give people greater "benefit of the doubt".

Perhaps the hopeless people you describe are the product of a hopeless context - the "enterprise context" you mention. That culture seems to encourage intellectual sloth and shrugging ambivalence, and you give good examples.

> Go look at /r/sysadmin or /r/

Please, I'd rather not :)

> executives who believe they're above things like "phishing awareness campaigns

My goodness I've met them. They're basically paid too much. I had to make a humint/influence piece for a major bank in London. Cybersec referred to it as "the cock problem"; basically mostly male with high six figure salaries whose security weakness was they "don't give a fuck". Same kind of fellas who would get pissed-up and drive their Aston Martin DB into a children's play-park. Major liability. They've learned they can transgress with impunity and just use money to solve it. What do they care if other people's money gets hacked? Not the best model for business, which requires a more upright mind-set to excel at. But banks don't exactly need to compete in a real business world.

> Technical measures are much cheaper and vastly more effective

Only in the short term. You'll need to forever keep your technical measures one step ahead of the mixture of malice and idiocy out there. A changed culture replicates and even grows itself.

Re: Brave New Trusted Boot World

#119

Earlier quoted context omitted.

For applications, tools, even most libraries - yes. But this was one of the critical elements of the system and they had to fork the entire distro because the way it was done actually made the choice more limited.

>But this was one of the critical elements of the system and they had to fork the entire distro because the way it was done actually made the choice more limited. This isn't very accurate. When Debian decided to switch to systemd, they also agreed to support other inits in the distribution. This wasn't good enough, so Devuan itself was forked before this decision was made. The end result is that Debian had less peopl…

> they also agreed to support other inits in the distribution.

That's true, but with systemd being the only init that packages had to support. Accordingly many package maintainers choose to only support systemd.

So if you want to run Debian without systemd, you have to be prepared for your fave packages to drop support for the other inits. It follows that you can't rely on the Debian package repository. So to support a Debian-like system without systemd, you have to fork the whole repository.

Re: Brave New Trusted Boot World

#120
I fail to see what all the panic is about. All of the SystemD tools mentioned here (iirc) don't actually rely much on SystemD proper and especially systemd-boot and the boot stub are just SystemD in name (I use both).

But regardless, this entire article is about how to have an actually secure boot on Linux (and not remote attestation), something which is certainly good for the user. Otherwise you're actually more easily susceptible to malicious actors stealing your data on the system you "trust". None of the steps listed here require trusting anyone other than the TPM (which is admittedly a flaw so long as we cannot audit them) and you can even use your own keys in pretty much all cases (provided -as discussed in other comments- MS hasn't f'd that up). I personally use a boot-stub based booting method with my own SB keys (but ironically, don't encrypt my root, so go figure), so I can vouch for the fact that it was actually quite painless to setup. Please don't jump down the slippery slope before you actually try these methods and realize that this is just as easy to deploy (you only need to disable secure boot first) and certainly a more secure option than using shim and an unsecured initrd.

Also, I don't understand where remote attestation entered the conversation here, and I also don't see why that can't be a community based thing (al la let's encrypt is now everyone's CA) where you can choose your providers or even roll it yourself.

Post reply on HN