Live data from Hacker News

Authenticated Boot and Disk Encryption on Linux (2021)

0pointer.net

1–10 of 75 posts

Re: Authenticated Boot and Disk Encryption on Linux (2021)

#2
If you're interested in this topic, the 5th "System Boot and Security" LPC microconference" is on Sep 18, https://lpc.events/event/18/sessions/201/#20240918

  Developing trustworthy Linux-based systems in an open-source way
  Common git repo for hosting Boot-firmware
  Accelerating Linux Kernel Boot-Up for Large Multi-Core Systems
  Leveraging and managing SBAT revocation mechanism on distribution level
  Using U-boot as a UEFI payload
  Measured Boot, Secure Attestation & co, with systemd
  Secure Launch - DRTM solution on Arm platforms
  no more bootloader: please use the kernel instead
  OF != UEFI

Re: Authenticated Boot and Disk Encryption on Linux (2021)

#4
I'm surprised that the author doesn't mention Pureboot [0] or even Heads [1], the most user-friendly [2] way to use TPM on Linux and authenticate the boot process along with /root, /boot directories.

Also, there is no Microsoft involved in my laptop, i.e., the author's statement

> Microsoft's certificates are basically built into all of today's PCs

is wrong. I enjoy the coreboot with Heads on my Librem 14 with my own keys.

[0] https://docs.puri.sm/PureBoot.html

[1] https://github.com/osresearch/heads

[2] https://puri.sm/posts/pureboot-101-first-boot-first-update-a...

Re: Authenticated Boot and Disk Encryption on Linux (2021)

#5
> the attacker takes the harddisk from your laptop while you aren't watching

> You'll never notice they did that.

Won't you be safe if you put a colorful nail polish to your laptop screws and take picture of its pattern? Then you regularly compare the actual pattern with your picture.

Re: Authenticated Boot and Disk Encryption on Linux (2021)

#6
post #4

I'm surprised that the author doesn't mention Pureboot [0] or even Heads [1], the most user-friendly [2] way to use TPM on Linux and authenticate the boot process along with /root, /boot directories. Also, there is no Microsoft involved in my laptop, i.e., the author's statement > Microsoft's certificates are basically built into all of today's PCs is wrong. I enjoy the coreboot with Heads on my Librem 14 with my own…

He's generally (I suspect p>99, probably a 9 more by volume) correct with his statement.

Re: Authenticated Boot and Disk Encryption on Linux (2021)

#7
post #6
post #4

I'm surprised that the author doesn't mention Pureboot [0] or even Heads [1], the most user-friendly [2] way to use TPM on Linux and authenticate the boot process along with /root, /boot directories. Also, there is no Microsoft involved in my laptop, i.e., the author's statement > Microsoft's certificates are basically built into all of today's PCs is wrong. I enjoy the coreboot with Heads on my Librem 14 with my own…

He's generally (I suspect p>99, probably a 9 more by volume) correct with his statement.

You are right, however the existence of alternatives is extremely important and should always be mentioned.

Re: Authenticated Boot and Disk Encryption on Linux (2021)

#8
post #7
post #6

Earlier quoted context omitted.

He's generally (I suspect p>99, probably a 9 more by volume) correct with his statement.

You are right, however the existence of alternatives is extremely important and should always be mentioned.

If you're Lennart, the existence of alternatives is a nuisance, so no need to give them free publicity.

Re: Authenticated Boot and Disk Encryption on Linux (2021)

#9
post #7

Earlier quoted context omitted.

You are right, however the existence of alternatives is extremely important and should always be mentioned.

If you're Lennart, the existence of alternatives is a nuisance, so no need to give them free publicity.

Good point. He's trying to widen the extent of systemd (and Microsoft?) yet again.

Re: Authenticated Boot and Disk Encryption on Linux (2021)

#10
post #5

> the attacker takes the harddisk from your laptop while you aren't watching > You'll never notice they did that. Won't you be safe if you put a colorful nail polish to your laptop screws and take picture of its pattern? Then you regularly compare the actual pattern with your picture.

I have a laptop with a soldered in disk! Check mate mofo! All for our safety of course!
Post reply on HN