Hmm, I'm not sure about that. I went the Crouton route on my $169 Chromebook, and now I have both ChromeOS and Ubuntu. Plus I can switch between them quickly. And if I understand Crouton, the chroot is actually using the same kernel and drivers as ChromeOS. I haven't had any driver issues. And it's easy to set up encryption for your chroot. I think it's a good solution.
How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
121–130 of 179 posts
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#122So, the solution to the uncertain threat of airlines picking your luggage and stealing your computer or its data is... giving over your data to somebody that it's certain it's spying on you and whose business model is to comb over your data. How is this not "you won't catch me, I'll just throw myself off a bridge"? Also, termux has ~600 packages. Debian has 50,000. Besides the basics, you're liable to need packages y…
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#123One of the BIGGEST drawbacks using a Chromebook with 11.6 inch screen that nobody here talks about yet, is the grainy and crappy 1366 x 768 screen resolution! I've been a long time Macs guy anything inferior than RetinaDisplay will considerably straining my eyes before I am used to it. Dell XPS 13 included.
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#124Well, it's possible to temporarily unlock firmware write protection and replace Google key with your own and run self-signed kernels and arbitrary distribution securely. But indeed, I haven't heard of anyone actually going through the effort to do so.
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#125I'm not sure how much extra "security" you're really getting out of staying strictly within ChromeOS. Yes, Secure Boot is disabled. However, the ChromeOS partition is still encrypted, and you can manually encrypt any of your crouton chroot environments, so someone looking at the thing still wouldn't be able to peek into the contents. If you're asked, "Why is this in Developer Mode?", you can answer, "I'm a developer.…
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#126Earlier quoted context omitted.
Is it not currently possible to install any GUI-based IDEs into Chrome OS?
You can currently only use web based IDEs or Android based IDEs in Chrome OS. There are some good web ones (Cloud9) out there and even a few Android based ones (AIDE). You won't be running any Windows or Linux IDEs though (because Chrome OS is not either of those.)
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#127I had computers that failed before, and usually I could manage to repair them somehow, most often by using a linux liveUSB, but with this chromebook, I've tried many things but I could not do anything. No access to BIOS, not bootable USB, nothing. Complete black box.
So I'm not sure I'll buy an other chromebook anytime soon.
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#128So, the solution to the uncertain threat of airlines picking your luggage and stealing your computer or its data is... giving over your data to somebody that it's certain it's spying on you and whose business model is to comb over your data. How is this not "you won't catch me, I'll just throw myself off a bridge"? Also, termux has ~600 packages. Debian has 50,000. Besides the basics, you're liable to need packages y…
It might be better to give your data to someone who has to tell you how they're spying on you, than to somebody who legally shouldn't be able to but does so anyway.
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#129I have been using the YubiKey for over a year now, and the novelty wore off. I lost my key a couple of weeks ago and was surprised how easy it was to get back into my accounts with just my phone. There is no point in using something like that if providers allow you to failover to more conventional authentication methods without any hassle; the keys are useless. They are not going to add manual verification for a coup…
Depends on the provider. From some quick Googling Lastpass at least requires email verification before disabling Yubikey support. https://lastpass.com/support.php?cmd=showfaq&id=2546 Even for providers that do provide seamless failover, the inevitable "we see you requested an account recovery" email would serve as useful canary to know you're being targeted.
That was the whole point of my comment. It is up to the vendor and vendors do a horrible job.
> the inevitable "we see you requested an account recovery" email would serve as useful canary
There is nothing useful here. They are allowing you to bypass a secure key with a dumb email confirmation.
Your idea of a 'useful canary' is great; until you get rooted at 5 AM on a Monday morning and that email disappears before you wake up.
Re: How Chrome OS, Termux, YubiKey and Duo Mobile make for great usable security
#130Earlier quoted context omitted.
Indeed, how dare they suggest that Google would track! They would never do such a thing!
If the claim being made was that they track your usage of their products, that would have been a reasonable response. But the claim being made is that they continuously monitor you through the webcam and microphone. That is extremely bold and, may I say, complete tinfoil nuttery.
Can't imagine what recording webcams would do- but I suppose it might be effective for something.