Live data from Hacker News

Ask HN: How do you trust that your personal machine is not compromised?

news.ycombinator.com

171–180 of 469 posts

Re: Ask HN: How do you trust that your personal machine is not compromised?

#171
post #20
post #9

Here's a short, fairly practical guide that you might find helpful: https://www.ncsc.gov.uk/files/Cyber-Essentials-Requirements-... . It is aimed mostly at small businesses, but I find a lot of the guidance to be pretty relevant to my personal IT. My even shorter (and incomplete) summary of the document would be: configure your router and firewall; remove default passwords and crapware from your devices; use a lock s…

Do you lock your computer every time you leave your desk? And do you always check for keylogger thumbdrives and such?

Yeah, colleagues have happened once, then never again. I use a Laptop with a Dockingstation for work and take the Laptop home with me every time I leave so I would have noticed if this would have happened.

When home, I always have to lock or my cat would typeeeeeeeeawww

Re: Ask HN: How do you trust that your personal machine is not compromised?

#172
post #152

The Librem 14 has a neutered Intel chip (no ME) among other things. My favorite privacy/freedom-respecting laptop. https://shop.puri.sm/shop/librem-14/

That looks nice enough. Is it custom built, or a 3rd party laptop that is modified?

Custom laptop hardware made in China then ME neutered and flashed with open firmware in the US.

Re: Ask HN: How do you trust that your personal machine is not compromised?

#173
post #102

Earlier quoted context omitted.

Lock my computer: Always[1][2]. Check for keylogger thumbdrives: I use a laptop so it would be immediately obvious. But now that you say it I haven't checked the charger USB-outlet on the back of my cabled keyboard. [1]: it has happened I have failed. Once a year or something. [2]: I sometimes try to allow myself to go downstairs in my own house to fetch a cup coffe without locking when I am alone, but I find it so s…

What bugs me is when this is applied to remote workers in a way that seems optimized for in-office environments. For example IT enforces that your screen becomes locked after 15 minutes of inactivity and also ties in your local computer 's user login password to your SSO login to access everything. It's a contradiction around password best practices. If you force people to input their password multiple times a day th…

> What bugs me is when this is applied to remote workers in a way that seems optimized for in-office environments.

> For example IT enforces that your screen becomes locked after 15 minutes of inactivity

If your OS is MS-Win, try playing an audio file when you don't want the auto-lock to go off. Provided IT's "checkbox security" parameters [1] did not include turning this off, MS-Win does not timeout lock the system if an audio file is playing, which makes playback of an audio file a way to prevent the timeout auto-lock from happening. Note that this won't help with any 'presence' indicators that go "idle" or "away" with no activity for some time.

If this works, then you can create an audio file of 'silence' with sox to use to play back when you don't want the auto-lock to trigger:

   sox -n silence.wav trim 0 10:0.0
Creates a ten minute long wav of 'silence'. If you want it smaller, compress the wav with lame into an mp3 or fdkaac into an aac file. Then launch playback of the silence file, and set windows media player to "loop" when it reaches the end of the file.

[1] Much corporate/govt. IT "security" is "checkbox security". It is the equivalent of IT having a "compliance form" with a long list of "configured settings" with check-boxes next to each, and so long as they can go down the form and "check all the boxes" they deem their setup "secure". Whether it is actually secure is not important, just that it "checks all the boxes" on the "compliance form".

Re: Ask HN: How do you trust that your personal machine is not compromised?

#174
post #9

Here's a short, fairly practical guide that you might find helpful: https://www.ncsc.gov.uk/files/Cyber-Essentials-Requirements-... . It is aimed mostly at small businesses, but I find a lot of the guidance to be pretty relevant to my personal IT. My even shorter (and incomplete) summary of the document would be: configure your router and firewall; remove default passwords and crapware from your devices; use a lock s…

> enable anti-malware if your OS has it . . . Would be interested in hearing other things Given the most common network activity is web browsing, it seems like enabling protections in the browser is becoming mandatory for the security-conscious. For me this amounts to enabling NoScript and uBlock[edit: [0]] plugins in Firefox, desktop and mobile versions, and disabling or locking down various "features". An additiona…

>Given the most common network activity is web browsing, it seems like enabling protections in the browser is becoming mandatory for the security-conscious.

What I am looking for is an easy way to run something like a LiveCD OS in a VM for browsing. The problem is that I have never found a decent LiveCD that has Firefox with all of the mandatory extensions (uBlock Origin, etc...). I guess I could customize my own LiveCD, but last I looked into it, doing so seemed complex and too time consuming to figure out.

Posting this in the hopes of being steered towards a simple solution or to inspire someone to create one.

Re: Ask HN: How do you trust that your personal machine is not compromised?

#177
post #102

Earlier quoted context omitted.

Lock my computer: Always[1][2]. Check for keylogger thumbdrives: I use a laptop so it would be immediately obvious. But now that you say it I haven't checked the charger USB-outlet on the back of my cabled keyboard. [1]: it has happened I have failed. Once a year or something. [2]: I sometimes try to allow myself to go downstairs in my own house to fetch a cup coffe without locking when I am alone, but I find it so s…

What bugs me is when this is applied to remote workers in a way that seems optimized for in-office environments. For example IT enforces that your screen becomes locked after 15 minutes of inactivity and also ties in your local computer 's user login password to your SSO login to access everything. It's a contradiction around password best practices. If you force people to input their password multiple times a day th…

The issue is more other members of your household. Your roommate, kids, spouse, etc. Policy and regulatory requirements don’t allow incidental disclosure to people like that, and the company has no relationship with them.

I dealt with this as a policy issue recently. Controls like aggressive screen lockouts are one of the few options available to allow some categories of workers to work outside of a company controlled premises.

The argument that you live alone etc is irrelevant as I have no idea (and don’t want to know) whether that’s true. I can tell you that people have done shockingly dumb things with remote work and the company has to try to control risk as best it can.

Re: Ask HN: How do you trust that your personal machine is not compromised?

#178
post #41
post #19

Earlier quoted context omitted.

What about publicly known backdoors in your hardware? https://www.techrepublic.com/article/is-the-intel-management... There is hardware that doesn't contain those at least, but it doesn't break power records.

I don't consider it practical to take any countermeasures to the possibility of this threat. I think there's a ~10% chance it's a backdoor, and if it is, there's a 98% chance it would be at the behest of a branch of the US government, and I'm not currently an adversary of theirs. (This is not an argument for mass surveillance, it's just a practical assessment of the risk).

Just to be clear, the question of whether it's a backdoor or not doesn't matter for whether bad actors use it. The capabilities are rather well known. Its vulnerabilities aren't, but vulnrabilities do not a backdoor make.

Re: Ask HN: How do you trust that your personal machine is not compromised?

#179
post #95

Earlier quoted context omitted.

Since you mention routers, I’m curious what brand you use. Since Ubiquity started fown the cloud-first path I’ve switched to Mikrotik. While they do seem to have regular CVEs (which is good, I think?), they also don’t seem to have a public bug bounty program.

> Since Ubiquity started fown the cloud-first path I’ve switched to Mikrotik I was thinking about getting a Ubiquity router because it has good support for setting up wired VLANs without needing to go down the path of finding a solid OpenWrt router. Is it really true that you can't access the router's dashboard and configure things without associating an online account to your router?

It's definitely still possible to use without cloud now, what I meant by "started down the path" is that it seems like the direction of the company is not aligned with what I want.

I was in the market for more hardware and I had to decide whether to increase my investment in Ubiquity or make a change, and I chose the latter.

Re: Ask HN: How do you trust that your personal machine is not compromised?

#180
post #162

Earlier quoted context omitted.

iOS is a proprietary OS making security research unreasonably difficult with new setbacks on every new version. It can only be regarded as reasonably private and secure if you trust the Apple marketing team.

My understanding is that Apple has gotten a lot better about this with their bug bounty payouts and providing debug hardware to researchers, and it’s not like there’s not a ton of proprietary code running on most consumer android devices. I would also assume the fact that their vertical integration all the way down to silicon is an advantage here as well.

In Android you at least have the choice to run a fully open source OS and open source apps, albeit with some driver blobs.

With the exception of the blobs, everything on Android is auditable.

Meanwhile very little of MacOS or iOS is auditable.

Personally I do not use or trust any of the above, but if forced to choose Android is worlds ahead of iOS in terms of publicly auditable privacy and security.

You cannot form reasonable confidence something is secure unless it can be readily audited by yourself or capable unbiased third parties of your choosing. This means source code availability is a hard requirement for any security claims. Even if you had teams de-compile everything you could never keep up with updates.

Not all open source code is secure, but all secure code is open source.

Post reply on HN