Live data from Hacker News

Safeboot: Booting Linux Safely

safeboot.dev

21–30 of 61 posts

Re: Safeboot: Booting Linux Safely

#21
post #6

Earlier quoted context omitted.

In its typical configuration, Secure Boot can't provide any anti-theft guarantees because an attacker could just replace the contents of the disk with a new Windows installation and the workstation would be usable for them. Secure Boot as it is configured by Windows only prevents malware from inserting itself into the boot process, since all Windows installations use the same signature. Bitlocker only prevents attack…

Hmmm, is it theoretically possible to sign the Windows bootloader (?) with your own custom keys to ensure that someone couldn't just fire up a stock Windows image? Though I'm not sure what sort of management challenges that would present if Microsoft ever decided to update their bootloader. Looking at the Microsoft documentation, doing this with SecureBoot could be pretty complicated: https://docs.microsoft.com/en-us…

I havent tested personally but this seems to suggest that you can't re-sign the bootloader: https://docs.microsoft.com/en-us/previous-versions/windows/i...

> "Windows boot components: BootMgr, WinLoad, Windows Kernel Startup. Windows boot components verify the signature on each component. Any non-trusted components will not be loaded and instead will trigger Secure Boot remediation."

Plus, you would need to add some kind of check to verify that it's actually booting your image, or else the attacker could just copy your bootloader files.

Re: Safeboot: Booting Linux Safely

#22
So what about this:

- Copy GRUB, bootlines for your system, your kernel and initrd to a WORM media like a bootable CD-ROM.

- Boot using CD-ROM.

- When boot completes, remove the CD-ROM.

Now you can't attack my boot kernel or boot process because I've just physically separated it from the system and taken it with me. Even if it was there, the media is read only so you can't modify it.

If I need to upgrade, I need to burn a new CD. CDs are cheap.

Using actual CDs would be impractical for many users, but a parallel could be implemented on a system with micro-SD card readers supporting removeable media and a physical read/write or connection switch. Which, if we're talking about physical switches for camera and mic, why not boot files?

Re: Safeboot: Booting Linux Safely

#24

So what about this: - Copy GRUB, bootlines for your system, your kernel and initrd to a WORM media like a bootable CD-ROM. - Boot using CD-ROM. - When boot completes, remove the CD-ROM. Now you can't attack my boot kernel or boot process because I've just physically separated it from the system and taken it with me. Even if it was there, the media is read only so you can't modify it. If I need to upgrade, I need to b…

Hmmm.

This implies that you have set your boot order to CD-ROM first, so anyone can - say - boot their own system on your machine from CD and either access your data or make a dd-copy of your disk and look at it later.

You need also to password protect your BIOS so that first device in boot order is hard disk and settings cannot be changed (without BIOS password).

Depending on the BIOS this change in booting order could be possible at boot time (providing the password) or a reboot would be needed.

Re: Safeboot: Booting Linux Safely

#25
post #11
post #8

Earlier quoted context omitted.

Boycott AMD, and obviously Intel [0]. Doesn’t really leave a lot of options. [0] https://libreboot.org/faq.html#intel

Well there is POWER[0], not that it's a very affordable choice, the cheapest motherboard + cpu costing $1,732.07 [0] https://www.raptorcs.com/content/BK1B01/intro.html

Is ARM an option? I know in practice many ARM systems rely on blobs, but it's not clear to me that that's universal.

Re: Safeboot: Booting Linux Safely

#26
post #24

So what about this: - Copy GRUB, bootlines for your system, your kernel and initrd to a WORM media like a bootable CD-ROM. - Boot using CD-ROM. - When boot completes, remove the CD-ROM. Now you can't attack my boot kernel or boot process because I've just physically separated it from the system and taken it with me. Even if it was there, the media is read only so you can't modify it. If I need to upgrade, I need to b…

Hmmm. This implies that you have set your boot order to CD-ROM first, so anyone can - say - boot their own system on your machine from CD and either access your data or make a dd-copy of your disk and look at it later. You need also to password protect your BIOS so that first device in boot order is hard disk and settings cannot be changed (without BIOS password). Depending on the BIOS this change in booting order co…

> You need also to password protect your BIOS so that first device in boot order is hard disk and settings cannot be changed (without BIOS password).

You also have to make sure your BIOS can't be reset by removing the battery, doesn't have some administrative bypass or even a reset jumper. I've even seen a BIOS that reset to default boot settings when you remove all disks - and then gleefully boots from any attached USB disk.

Re: Safeboot: Booting Linux Safely

#27

If every Linux user would boycott AMD to release their source, then we could have libreboot: https://libreboot.org/amd-libre.html ME vs PSP isn't much of a choice. Of course POWER might be an option eventually, but isn't for most of us currently.

It looks like that stuff was hot 3 years ago. Is there a newer (more likely to pay off) push? I'd happily tell AMD that I'm in the market for an expensive new system and I'd instantly go with Ryzen if it were open. As it stands now I'm leaning Intel because it's the devil I know.

I don't understand. Intel has ME, AMD has PSP, neither makes any particular effort to support libreboot (although I'm pretty sure coreboot can work with both if the manufacturer wants, because Chromebooks do that). Unless you believe that Intel is more open, why would you prefer it? It appears to me that they're equally security-unfriendly, but with AMD at least winning on price and performance.

Re: Safeboot: Booting Linux Safely

#28
I really like the philosophical approach here, even if it's too finicky to put in practice today. I'm really sick of everything being made "secure", when in fact the "security" is for someone other than the legitimate user of the thing. Phones, laptops, physical security systems, cars, the list goes on.

There was a post here yesterday (https://news.ycombinator.com/item?id=23149771) about the (in)security of Linux, but the primary purpose of an OS is utility, not merely security. The leadership of the Linux project made very smart analyses of what priorities come first. Despite there being billions of insecure old devices scattered about, running old kernels, I think the kernel authors made the right call.

The problem rests with the manufacturers who abandoned support for those devices and left no escape route for users to update the kernels themselves. Most disgusting are these phone and car manufacturers, and apps, which have enabled wholesale spying on users for many years now. These devices are literal bugs, reporting realtime locations, conversations, and who knows what else to Big Brother.

Its a pleasure to see that some people still care enough to make the world a better place, in a way I can understand.

Re: Safeboot: Booting Linux Safely

#29
post #11

Earlier quoted context omitted.

Well there is POWER[0], not that it's a very affordable choice, the cheapest motherboard + cpu costing $1,732.07 [0] https://www.raptorcs.com/content/BK1B01/intro.html

Is ARM an option? I know in practice many ARM systems rely on blobs, but it's not clear to me that that's universal.

There is nothing like "ARM" in the market.

There is CPU/SoC X by Y, built on top of a license from ARM.

So you would have to boycott N companies instead of just AMD & Intel :( And even more so, since all their customers are EOM that are happy to sign NDAs.

Re: Safeboot: Booting Linux Safely

#30
post #20

Slightly unrelated: I currently have a custom platform key, packet everything I need for booting into a single image (signed with the custom platform key) and everything else is in a fully encrypted partition (lvm2 on dmcrypt). "Decryption key" is inserted via keyboard on boot, which is not to everyone's liking but is what I want. It's not really hard to setup (on arch Linux) and works like a charm. ;-) Through the d…

That was exactly my motivation: there are tons of guides for setting up UEFI SecureBoot platform keys, yubikey tokens, TPM disk encryption, dmverity, etc, but all of them seemed to involve "type hundreds of commands with no mistakes and hope that your system still boots afterwards". It felt to me that each program represented a low-level library function that needed to be linked into a high-level tool to handle the c…

There's a way to encrypt the boot partition and have GRUB ask you for the boot partition key, but you're limited to LUKS1, and the decryption process is slow as molasses, since it's implemented inefficiency directly in the GRUB code, because the Kernel's faster code isn't loaded yet. It's also probably full of side channel leaks. Signing the kernel and ramdisk is probably the better option...
Post reply on HN