Live data from Hacker News

Ask HN: How do you trust that your personal machine is not compromised?

news.ycombinator.com

351–360 of 469 posts

Re: Ask HN: How do you trust that your personal machine is not compromised?

#351
For my part, after considering this very question in the past, the answer is that the question is wrong.

The question is: is there some reason to trust, and the answer is: no.

In my opinion, any and all general computing devices sold to the mass consumer market are already compromised in some shape or form as they roll out from the factories -- otherwise such things would simply not be sold in large quantities.

Re: Ask HN: How do you trust that your personal machine is not compromised?

#352

ex-AOSP dev here Android and ChromiumOS are likely the most trustable computing platforms out there; doubly so for Android running on Pixels. If you don't prefer the ROM Google ships with, you can flash GrapheneOS or CalyxOS and relock the bootloader. Pixels have several protections in place: - Hardware root of trust: This is the anchor on which the entire TCB (trusted computing base) is built. - Cryptographic verifi…

Windows does all of those, in addition to fine grained access controls. I would go so far as to say that the Chromium sandbox implementation is better than on Android because of the ability to completely de-privilege processes.

Windows struggles with feature adoption though. Win11 helped with the TPM requirement and features on by default, but MSIX apps are still underrepresented so userspace sandboxing is weaker. Windows virtualization-based security is great though, imo it's a significant advantage over Android

Re: Ask HN: How do you trust that your personal machine is not compromised?

#353
post #346

Earlier quoted context omitted.

I've never used Qubes. Rather I heavily segment with manually configured VMs. The ones that run proprietary software (eg webbrowsing, MSWin, etc) generally run on a different machine than my main desktop. It's quite convenient as I can go from my office to the couch, and I just open up the same VMs there and continue doing what I was doing. I define the network access for each VM in a spreasheet (local services and I…

Thinking of my kids' future has also made me much more energy-conscious. Meaning I've stopped running my VM host 24/7 like I was, because neither ESX nor Proxmox is really set up for saving energy easily (automated suspending and waking, etc). Which is a shame, since I'm actually finding that with gigabit fiber at home, even on mobile connections I can work pretty decently on homelab VMs. Running something like it on…

I feel like this is the all too common pattern of individuals taking environmental responsibility to absurd levels, while corporations dgaf. How much electricity is burned in datacenters, especially doing zero-sum surveillance tasks?

My Ryzen 5700G ("router") idles around 20-25W, which seems like a small price to pay to not be at the mercy of the cloud. That's around 60 miles of driving per month (gas or electric), which seems quite easy to waste other ways.

My Libreboot KGPE ("desktop/server") burns about 160W. This is much higher than a contemporary computer should be, but that's the price of freedom. I could replace it with a Talos II (~65W from quick research), but the payback for electricity saved would take several decades.

To cut back on the environmental impact, I do plan to install solar panels with battery storage, which will also replace the need for UPSes. I've got another KGPE board for which it's interesting to think about setting up as a parallel build host, only running during sunny days rather than contributing to electricity storage requirements.

Re: Ask HN: How do you trust that your personal machine is not compromised?

#354

Earlier quoted context omitted.

I think, perhaps ignorantly, That may prevent some human being or intelligent agent specifically targeting your nas. I don't think it would help against situations where your primary system is being encrypted for a while, and thus your backups eventually get overwritten with bad stuff.

The data being backed up is in tiers of importance or 'frequency of change', and based on this the backups are staggered, some daily, some weekly. I wouldn't often go a full week without checking some file or other, so I think I'd know pretty swiftly if I got infected with an encrypting ransomware virus - hopefully quickly enough to minimise damage. I also do off-site backups on occasion, so I could roll back to the…

>The data being backed up is in tiers of importance or 'frequency of change', and based on this the backups are staggered, some daily, some weekly.

This right here is the key to backups: triage your data to understand what is truly important. I roughly put things into three buckets

- Priority 1 - potentially disastrous if lost. Financials, taxes, legal documents, and password vaults. The nice thing about most of these documents is that they are immutable and likely append-only (eg you only have one set of 2020 taxes). For most people, this amount of data should be well under 1GB and require only sporadic backups. Which means you can purchase a bolus of $10 thumb drives, encrypt the collection, and leave them everywhere. Mail an annual copy to mom, leave one in your bag, at the office -wherever.

- Priority 2 - anything you created which does not fall into Priority 1. Home pictures, videos, your 1000 half-baked programming projects, etc. Potentially a much larger collection for which a real backup system becomes necessary.

- Priority 3 - everything else which is theoretically replaceable. The archive of music you "acquired", backups of youtube videos, personally ripped DVD collection, etc

Re: Ask HN: How do you trust that your personal machine is not compromised?

#355
post #95

Earlier quoted context omitted.

Since you mention routers, I’m curious what brand you use. Since Ubiquity started fown the cloud-first path I’ve switched to Mikrotik. While they do seem to have regular CVEs (which is good, I think?), they also don’t seem to have a public bug bounty program.

> Since Ubiquity started fown the cloud-first path I’ve switched to Mikrotik I was thinking about getting a Ubiquity router because it has good support for setting up wired VLANs without needing to go down the path of finding a solid OpenWrt router. Is it really true that you can't access the router's dashboard and configure things without associating an online account to your router?

> Is it really true that you can't access the router's dashboard and configure things without associating an online account to your router?

That might be true for their UniFi line, but EdgeMAX devices work fine without an online account. EdgeRouters run a fork of Vyatta, with configuration files and command line operations that are fairly easy to work with. They also have a web UI for common configurations, though I have little experience with it.

A bit of warning: EdgeMAX support has been declining in recent years. Security updates are still published, but bugs don't seem to be addressed as quickly or consistently as they were in the past, and some forum users have expressed doubts about what kind of support will exist in the future. That said, my equipment is still doing fine.

I think OpenWRT has been ported to at least one Ubiquiti router, so that might be a good fallback if EdgeOS support ever ends. I wonder if anyone here has tried it.

Re: Ask HN: How do you trust that your personal machine is not compromised?

#356

Earlier quoted context omitted.

OpenBSD doesn't have proper sandboxing. If you download malware it can easily steal and upload your ssh keys.

> proper sandboxing Do jails not fulfill this?

OpenBSD doesn't have jails. Jails take effort to setup. It's much easier to just run the malware instead of going through the effort of making a jail for it.

Re: Ask HN: How do you trust that your personal machine is not compromised?

#357
post #285

Earlier quoted context omitted.

You asked why we would need to verify things he said. I explained it quite concretely. What part did you not understand? Edit: whether people are wrong about android security is orthogonal and whataboutism

My android comment was taking yours, turning it around and taking it to the extreme to illustrate a point. And no, I never asked why we would need to verify the security researcher’s claims (but sure, you should). 1. Dma54rhs says Apple’s (!) claims supposedly can’t be verified and that you need to take Apple’s word for it 2. I ask why not, provide a link to a talk about iOS security by a renown security researcher a…

You’re the one derailing from the actual topic, which was broadly can we trust our devices and specifically can we trust iOS, by muddying the water with what-about-android. The question wasn’t which we can trust more, the question was whether and how much we can trust Apple.

You can’t verify that iOS is doing what Apple says that it’s doing, because you can’t read the code. You can’t trust that Apple perfectly understands their product, because it’s extremely complicated, and therefore you can’t just take their word for it. I’ll state that the check here, although it’s painfully obvious, is that exploits happen. Researcher opinions are fine, but facts are better.

None of this is in any way contentious or new, it’s the exact debate about open-vs-closed that we’ve been having since the beginning of software.

Re: Ask HN: How do you trust that your personal machine is not compromised?

#358
post #240

Earlier quoted context omitted.

> Linux kernel is simply not equipped to run trusted code and untrusted code in the same memory. Just for interest sake, is Linux better or worse than MacOS, iOS and Windows at this?

Windows 10 and later run drivers and parts of the kernel on their own hypervisor slots. macOS has SIP. GNU/Linux is still not there doing this out of the box.

I'm curious about your take on this.

Would you say macOS, iOS, Windows are more trustable than FOSS OSes like Fuschia or ChromeOS, Android, or even QubeOS and Tails?

If not, where else ChromiumOS / Android lack (keeping in mind the embedded nature of the latter)?

How long do you think before viable open firmware / open hardware computing devices show up?

Thanks.

Re: Ask HN: How do you trust that your personal machine is not compromised?

#359
post #310
post #274

Earlier quoted context omitted.

And yet law enforcement seems to be able to open up Android phones without issue, but has problems with iPhones. Is this still the case?

Law enforcement has never had problems with iPhones. iPhones in the default configuration back up all data to iCloud with Apple keys, allowing Apple and the FBI to read all of the photos and messages on a device at any time, without the device. The "Apple vs FBI" thing was a coordinated PR campaign following the Snowden leaks to salvage Apple's reputation. https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv.…

Unsure why you're ignoring the difference of unlocking an iPhone to access the data on the phone compared to accessing data on iCloud.

Re: Ask HN: How do you trust that your personal machine is not compromised?

#360

I worry so much more about the dumb hardware locks and secure enclaves, OS features etc. I find the risk of a compromised machine to be so much less of an impact on my life than my computer telling me I am not allowed to do something. This is my computer, let me tell it what to do. I hate how much of my time is wasted by all this security stuff. Infinitely more so than had been wasted by actual malware over the last…

Root detection is about reducing risk to companies, presumably sideloading results in substantially increased risk. It’s not about you, it’s about their bottom line, but it can also help prevent grandma from losing their life savings.

I’m a security engineer and know what I’m doing and agree there’s some level of security theatre, but it you’re not worried about losing Crown Jewels from a compromise you’re most probably uneducated or arrogant.

Post reply on HN