Earlier quoted context omitted.
Yep. I find it baffling that people in the tech industry (who should know better) are enthusiastic about vehicle infotainment systems, Apple CarPlay, Android Auto, etc. Keep it simple. Power, a 3.5mm audio connector, and a windshield suction mount. Something they can't screw up too badly. I can easily buy a new smartphone every 2 years, but a car I'm going to hold on to for more like 10. Why would I want to be stuck…
> Why would I want to be stuck with a 5-generation-old navigation/music player system when the car is still fine? Why would you be? Isn't this a solved problem? When you want to upgrade your entertainment system, you head to somewhere like Crutchfield or Sonic or Best Buy and buy a new one to plug in. In many cars, it takes less time to install a new car infotainment unit than it takes to buy a new iPhone from a carr…
ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
141–150 of 200 posts
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#142Earlier quoted context omitted.
DNS challenge is the worst of both: You have to manually add 60 something DNS entries, and remove them again. Just putting a public key in the DNS and being able to sign a CSR with the correspoding private key should be enough.
There are ACME clients that can automate the DNS challenge process.
If you have DNS managed by your domain registrar, this helps you very little.
So, for the average small site that’s neither made with a kit where the hoster has a one-click SSL solution, nor large enough to have their own nameservers, this is a real issue.
And yet, these sites are the target demography for LE.
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#143Earlier quoted context omitted.
I've been trying to convince , the owner/(brother of owner) of that desire.de site (btw not the official repo) to implement HTTPS and caching using Let's Encrypt and Cloudflare and not just rely on signed binaries but he's insistent that his method of just signing the binaries is sufficient secure. Maybe if sufficient number of people pester him about it. EDIT: On a related note, I've been trying to get the ddwrt guy…
Transferring signed packages over TLS only prevents the attacker from observing which particular packages are being updated, and that’s assuming the padding alone is sufficient to obscure identification by size. Otherwise signing packages is actually preferred, because you can do it offline, so that hacking the server is not enough to push malicious code.
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#144Earlier quoted context omitted.
I couldn't do this, I had to boot windows once to disable UEFI first. Didn't set up the wifi though.
Isn't that just a BIOS setting? Addmitedly I've not dealty with UEFI much.
> Windows 10 keeps the [Fast Startup] feature as Windows 8. (For more information, please refer to Windows 8-Introduction of [Fast Startup])
> Due to the reason, you CANNOT press F2 to enter BIOS configuration when booting the system.
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#145Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#146Earlier quoted context omitted.
Transferring signed packages over TLS only prevents the attacker from observing which particular packages are being updated, and that’s assuming the padding alone is sufficient to obscure identification by size. Otherwise signing packages is actually preferred, because you can do it offline, so that hacking the server is not enough to push malicious code.
But that assumes hardware vendors' signature verification code is correct -- and crypto is really hard to get right
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#147Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#148Earlier quoted context omitted.
How are Apple actively malicious?
Let's see here: * Started the trend of non-replaceable batteries in phones * Started the trend of non-replaceable batteries in laptops * Started the trend of locked-down devices where the owner can't decide what software to run * Custom screws in order to prevent people from fixing their devices * Custom enclosures in order to prevent people from replacing parts in their devices with commodity devices * Soldering in…
Also, I should point out that while Apple's phones don't let you install unapproved software, this isn't true of the Mac, which, unlike Microsoft-approved PCs[0], lets you install alternative operating systems (you can even boot to DOS!), disable its security features, etc.
[0] I know that MS do allow OEMs to allow disabling Secure Boot, but it's not required as of Windows 10. Meanwhile, Apple's computers don't have it in the first place!
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#149Earlier quoted context omitted.
Let's see here: * Started the trend of non-replaceable batteries in phones * Started the trend of non-replaceable batteries in laptops * Started the trend of locked-down devices where the owner can't decide what software to run * Custom screws in order to prevent people from fixing their devices * Custom enclosures in order to prevent people from replacing parts in their devices with commodity devices * Soldering in…
Right. These can also be interpret as their reason to make slimmer devices. People buying these products would presumably know what they're getting into.
Re: ASUS delivers BIOS/UEFI auto-updates over HTTP with no verification
#150Earlier quoted context omitted.
Right. These can also be interpret as their reason to make slimmer devices. People buying these products would presumably know what they're getting into.
How does needlessly soldering ram in make a device slimmer?