Live data from Hacker News

What is an SBAT and why does everyone suddenly care

mjg59.dreamwidth.org

241–250 of 276 posts

Re: What is an SBAT and why does everyone suddenly care

#241

Obviously people might screw up, but the spec included a way to revoke any signed components that turned out not to be trustworthy "trustworthy" according to who ? Remember that dystopia does not appear spontaneously, but steadily advances little-by-little. What's the summary? Microsoft (understandably) didn't want it to be possible to attack Windows by using a vulnerable version of grub that could be tricked into ex…

I guess in their defense the same attack can be used against any other OS so they're unintentionally protecting Linux as well, since they stated this was supposed to be a Windows-only system change. You can disable secure boot if you don't want to be secure. And, there is a way to disable the SBAT policy and keep secure boot if you want that, which is also insecure. Disable Secure Boot, login, sudo mokutil --set-sbat…

[dead]

Re: What is an SBAT and why does everyone suddenly care

#242

Obviously people might screw up, but the spec included a way to revoke any signed components that turned out not to be trustworthy "trustworthy" according to who ? Remember that dystopia does not appear spontaneously, but steadily advances little-by-little. What's the summary? Microsoft (understandably) didn't want it to be possible to attack Windows by using a vulnerable version of grub that could be tricked into ex…

I agree with everything except this:

> Things like TPM and "secure" boot were never envisioned for the interests of the user.

I am successfully using TPM with coreboot and Heads, with my own keys, to protect against boot attacks on my Librem 14 with Qubes OS.

Re: What is an SBAT and why does everyone suddenly care

#243
post #197

Earlier quoted context omitted.

I mean can you actually protect against the NSA? After Stuxnet, I fully trust that nation/state actors can infect whatever they put their mind to - I'd rather at least have control over my machine

If your adversary is a nation state, you've already lost. Which gives me another opportunity to quote from my favourite Usenix paper: "In the real world, threat models are much simpler (see Figure 1). Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@ virus-basket.biz.…

> If your adversary is a nation state, you've already lost.

Did you hear about Snowden?

Re: What is an SBAT and why does everyone suddenly care

#244

Earlier quoted context omitted.

It is usually possible to decrease your attack surface.

Unplug all your computing devices, put them in a safe, embed the safe in concrete, drop it all in the sea.

Just try Qubes OS with Heads.

Re: What is an SBAT and why does everyone suddenly care

#245

Earlier quoted context omitted.

I have had occasional issues with Windows and various flavors of Linux hibernating but nothing that happens with any regularity - at all - and nothing that can't be solved by simply rebooting.

I shouldn't have to reboot in order to fix sleep or hibernate. Their reason for existence is to avoid the need to shut down and restart.

Did you read anything else in my comment?

Re: What is an SBAT and why does everyone suddenly care

#246

Obviously people might screw up, but the spec included a way to revoke any signed components that turned out not to be trustworthy "trustworthy" according to who ? Remember that dystopia does not appear spontaneously, but steadily advances little-by-little. What's the summary? Microsoft (understandably) didn't want it to be possible to attack Windows by using a vulnerable version of grub that could be tricked into ex…

I guess in their defense the same attack can be used against any other OS so they're unintentionally protecting Linux as well, since they stated this was supposed to be a Windows-only system change. You can disable secure boot if you don't want to be secure. And, there is a way to disable the SBAT policy and keep secure boot if you want that, which is also insecure. Disable Secure Boot, login, sudo mokutil --set-sbat…

>But, I don't think that was their thought process at all.

Intent, being squishy and debatable matters far less than the outcome.

I can say that I never intended X, but in the end, X still happened. That it happened unintentionally assuages exactly no injury from X having happened.

Re: What is an SBAT and why does everyone suddenly care

#247

Earlier quoted context omitted.

You could if you want to, but if your distribution provides a UEFI bootloader (shim / grub / systemd-boot / whatever) signed by the default MS-trusted cert, or you're willing to set up everything yourself with your own certs, it doesn't hurt to enable it either (except when an incident like this happens).

The Mint forums pretty much tell everyone to blanket disable secure boot because nobody seems to know how to make it work, certainly not well enough to explain it to a beginner.

Maybe. From what I know of sbctl I think it would be fine for a beginner, but I can't say for sure because I use my own custom setup, not sbctl.

Re: What is an SBAT and why does everyone suddenly care

#248

Obviously people might screw up, but the spec included a way to revoke any signed components that turned out not to be trustworthy "trustworthy" according to who ? Remember that dystopia does not appear spontaneously, but steadily advances little-by-little. What's the summary? Microsoft (understandably) didn't want it to be possible to attack Windows by using a vulnerable version of grub that could be tricked into ex…

I guess in their defense the same attack can be used against any other OS so they're unintentionally protecting Linux as well, since they stated this was supposed to be a Windows-only system change. You can disable secure boot if you don't want to be secure. And, there is a way to disable the SBAT policy and keep secure boot if you want that, which is also insecure. Disable Secure Boot, login, sudo mokutil --set-sbat…

>But, I don't think that was their thought process at all.

Intent, being squishy and debatable matters far less than the outcome.

I can say that I never intended X, but in the end, X still happened. That it happened unintentionally assuages exactly no injury from X having happened. Intent, therefore can only be considered as at best, an aggravating factor on top of the outcome.

Re: What is an SBAT and why does everyone suddenly care

#249
post #194

Earlier quoted context omitted.

> Who is Microsoft to decide what others do on their machines? That would be an amazing rant had it only ended with "Sent from my iPhone". Since the Blaster worm incident two decades ago, we're in a new era where security at scale becomes the forefront responsibility of the companies developing the product. That includes writing more secure code, having more verifications in place, adopting more secure technologies,…

Blaster was Microsoft's own incompetence. CrowdStrike was CrowdStrike's own incompetence. They are free to fix the problems of their own doing. But messing with software you do not own, on machines you do not own, crosses a line and should be considered an act of aggression. What if some Linux distro releases an update that deletes any installations of Windows it finds "because Windows is insecure" (according to them…

> Blaster was Microsoft's own incompetence.

All security bugs are result of incompetence. Massive DoS incidents are result of scale. Use your magic wand, bring Linux to 90% desktop OS marketshare, and see how one malware destroys an order of magnitude more Linux devices than Windows.

> They want to give more control to Microsoft

No, they want secure defaults, not less control.

> And crimes happen because people still have freedom.

Okay, let me extend that whataboutism with "hey why do we have laws that limit people's freedom, let's remove all the laws if people are entitled to infinite freedom, and can be trusted with their judgement".

> Freedom to make mistakes

Not at the expense of harming others.

Re: What is an SBAT and why does everyone suddenly care

#250
post #194

Earlier quoted context omitted.

> Who is Microsoft to decide what others do on their machines? That would be an amazing rant had it only ended with "Sent from my iPhone". Since the Blaster worm incident two decades ago, we're in a new era where security at scale becomes the forefront responsibility of the companies developing the product. That includes writing more secure code, having more verifications in place, adopting more secure technologies,…

> When you have a billion devices running around the world, you can't say "hey we'll let this arbitrary group of billion people do what they think is best for them", because you then end up with Blaster worm, and the whole Earth falls apart. The bug is in the fact that billions of machines are running exactly the same proprietary software. Following the "virus" metaphor, having billions of identical organisms is how…

> The bug is in the fact that billions of machines are running exactly the same proprietary software.

What's the alternative?

Post reply on HN