When I travel, there is no way to decrypt my computers, since keys are with me. When I arrive home, I insert keys, start all computers, upgrade packages (automated), remove keys...
Brave New Trusted Boot World
151–160 of 178 posts
Re: Brave New Trusted Boot World
#152Earlier quoted context omitted.
This number diminishes every passing year, with only debian being a bastion of sanity on the "user friendly" side of the distro spectrum.
Debian only supports systemd though? No sure what you mean by bastion in the context of systemd. Devuan is the Debian non-systemd fork.
Re: Brave New Trusted Boot World
#153As somone who never really viewed systemd as a problem I'm starting to think the systemd "haters" were actually right, at least somewhat... Viewing Poettering as some kind malicious entity undermining projects sounds like a conspiracy theory. But now with him working for Microsoft his actions do look like a lot like the "embrace, extend, and extinguish" pattern to me. Yes, yes "Microsoft And now I am supposed to chee…
So if we want to actually change this, we should aim to create another CA, not attack sysD or secure boot(though its design is stupid to rely on Microsoft but it's too late now).
Re: Brave New Trusted Boot World
#154That said, I’m in the camp of: this is good, and a lot of the comments here are FUD (aka Poettering probably hasn’t read Brave New World, or at least this isn’t that).
Re: Brave New Trusted Boot World
#155Earlier quoted context omitted.
> they also agreed to support other inits in the distribution. That's true, but with systemd being the only init that packages had to support. Accordingly many package maintainers choose to only support systemd. So if you want to run Debian without systemd, you have to be prepared for your fave packages to drop support for the other inits. It follows that you can't rely on the Debian package repository. So to support…
I think the situation would have been better if the people opposed to Debian would contribute to better init script support then just forking it.
Devuan has init-script support for the packages in its repository. So it's open to the Debian maintainers to pull the scripts in; but they only want to support one init system, understandably. And the fact that nearly all other distros have systemd as a default init, it's natural that developers and maintainers are pleased with the systemd hegemony.
I'm just sorry that Debian made the decision it did. But Debian has always been the developers and maintainers; only incidentally the users. They were entitled to make that decision, and I think their process was exemplary.
[Edit] That "exemplary" process: actually I think it shouldn't have been pushed to the technical committee. It should have been a simple general resolution from the start. But I think the result would have been the same, and I found the debates very illuminating.
Re: Brave New Trusted Boot World
#156As somone who never really viewed systemd as a problem I'm starting to think the systemd "haters" were actually right, at least somewhat... Viewing Poettering as some kind malicious entity undermining projects sounds like a conspiracy theory. But now with him working for Microsoft his actions do look like a lot like the "embrace, extend, and extinguish" pattern to me. Yes, yes "Microsoft And now I am supposed to chee…
I don't trust these groups or corporations so I'll stick to custom keys for this stuff, but I think having a working group with a signed boot loader is much better than the current situation (Microsoft signs a shim that basically bypasses secure boot on some devices and then Linux users set up a Rube Goldberg machine of 4 different levels of bootloader to get verified boot working).
I'm running the MS shim right now and I don't see why the systemd shim would be worse in any way.
Re: Brave New Trusted Boot World
#157Earlier quoted context omitted.
It's not a "theoretical DRM use case" if you stop thinking in terms of movie piracy for a moment, and consider what's happening with banking apps on mobile platforms. Thanks to remote attestation, the custom ROM scene for Android is pretty much dead now, because there's little point of customizing the OS when it automatically makes important services no longer accessible from the phone.
That's the entire point. Your bank doesn't want you to run their software on your potentially vulnerable hardware.
In terms of practical security, custom ROMs are often safer than the forgotten and obsolete software left on a device when updates stop rolling out. Sandbox escapes and exploits to get root access are more realistic threats than airport security flashing a different OS through your phone recovery or some kind of conspiracy to stuff malware into an open source repository.
As long as you take care to only install software from reliable sources (i.e. download.lineageos.org, F-Droid.org) I don't see the problem.
Re: Brave New Trusted Boot World
#158Earlier quoted context omitted.
At least so far my bank hasn't prevented me from using my web browser on linux to access the banking website. But I am certain they will once Windows 11 gets enough traction in a few years.
Can you use your web browser for all functions of the banking app? E.g. for my bank the app is the only 2FA option that doesn't come with additional costs.
Re: Brave New Trusted Boot World
#159I fail to see what all the panic is about. All of the SystemD tools mentioned here (iirc) don't actually rely much on SystemD proper and especially systemd-boot and the boot stub are just SystemD in name (I use both). But regardless, this entire article is about how to have an actually secure boot on Linux (and not remote attestation), something which is certainly good for the user. Otherwise you're actually more eas…
> but ironically, don't encrypt my root, so go figure Oh man that takes me back. The last time I went down that rabbit hole was ~2015, I tried to implement a "fully encrypted" setup and started with Ubuntu (I know I know). Something something LUKS. I spent ~2 days tinkering with it and never got it to work, something with the setup flow was totally broken if you also tried to encrypt root (or boot? idk like I said it…
This worked fine.
Months later (in this case I just left it connected to a TV and occasionally used it for gaming or whatever) I let it do an OS upgrade and it forgot how to read its disk when it rebooted. I spent maybe 30 minutes trying to fix it (former heavy Gentoo user, so I'm comfortable troubleshooting boot—among other—issues) without making any progress at all, then decided that was the end of that particular check-in with desktop linux. Maybe next time (spoiler: nope, though for different reasons. But maybe the next next time...)
I haven't tried encrypting a Linux root disk since.
Re: Brave New Trusted Boot World
#160Earlier quoted context omitted.
I know my reasons for feeling worried about it but I wonder why you also dislike the idea of end user operating systems making it trivial for applications to take advantage of remote attestation?
Because it can snowball from "you may not access Widevine content on an unapproved device", which is of little significance to "you may not connect to the internet on a non government approved device" which is extremely dangerous.
This isn't a slippery slope, this is a vertical surface that was erected over seven years ago when SGX hit the market, just standing there.
Luckily the content I watch on Netflix is also freely available through torrents so I don't usually notice the difference, but the DRM fight was lost long ago. Whatever evil things the government is planning on enacting won't be beaten by someone telling the police officers that they use Arch btw.