Live data from Hacker News

Safeboot: Booting Linux Safely

safeboot.dev

41–50 of 61 posts

Re: Safeboot: Booting Linux Safely

#41

I really like the philosophical approach here, even if it's too finicky to put in practice today. I'm really sick of everything being made "secure", when in fact the "security" is for someone other than the legitimate user of the thing. Phones, laptops, physical security systems, cars, the list goes on. There was a post here yesterday ( https://news.ycombinator.com/item?id=23149771 ) about the (in)security of Linux,…

[deleted]

Re: Safeboot: Booting Linux Safely

#42

I really like the philosophical approach here, even if it's too finicky to put in practice today. I'm really sick of everything being made "secure", when in fact the "security" is for someone other than the legitimate user of the thing. Phones, laptops, physical security systems, cars, the list goes on. There was a post here yesterday ( https://news.ycombinator.com/item?id=23149771 ) about the (in)security of Linux,…

> I'm really sick of everything being made "secure", when in fact the "security" is for someone other than the legitimate user of the thing. It's less binary than that for me. Yes, the same technologies that keep my data secure also act as a buttress against jailbreaking. But people who want to jailbreak can simply choose less-secure devices, while I would personally not trade that security for greater hackability. T…

Apparently your threat model doesn't include governments and large corporations, who have done more enumerable harm (e.g. through the military-industrial-information complex) to people than small-time crooks ever have. Sometimes it seems more people want to live in prison (or a gilded cage), than in regular civilian life with all its attendant dangerous freedoms.

The point of the OP is that users can and deserve to have the reliability that cryptographically-secure boot systems provide, without the Big Brother backdoor.

Re: Safeboot: Booting Linux Safely

#43

I really like the philosophical approach here, even if it's too finicky to put in practice today. I'm really sick of everything being made "secure", when in fact the "security" is for someone other than the legitimate user of the thing. Phones, laptops, physical security systems, cars, the list goes on. There was a post here yesterday ( https://news.ycombinator.com/item?id=23149771 ) about the (in)security of Linux,…

> I'm really sick of everything being made "secure", when in fact the "security" is for someone other than the legitimate user of the thing. It's less binary than that for me. Yes, the same technologies that keep my data secure also act as a buttress against jailbreaking. But people who want to jailbreak can simply choose less-secure devices, while I would personally not trade that security for greater hackability. T…

[deleted]

Re: Safeboot: Booting Linux Safely

#44

Earlier quoted context omitted.

It looks like that stuff was hot 3 years ago. Is there a newer (more likely to pay off) push? I'd happily tell AMD that I'm in the market for an expensive new system and I'd instantly go with Ryzen if it were open. As it stands now I'm leaning Intel because it's the devil I know.

I don't understand. Intel has ME, AMD has PSP, neither makes any particular effort to support libreboot (although I'm pretty sure coreboot can work with both if the manufacturer wants, because Chromebooks do that). Unless you believe that Intel is more open, why would you prefer it? It appears to me that they're equally security-unfriendly, but with AMD at least winning on price and performance.

> It appears to me that they're equally security-unfriendly, but with AMD at least winning on price and performance.

I agree (although I'm not sure price and performance is significant enough to matter to me), the only reason I would go with Intel is that it's what I've been using for the last 20 years, and it's what I know. I had an AMD one time (late 90s/early 00s) and had a lot of problems with it. I know AMD today is much different than in the past, but I'm still wary whe the investment is one I will need to use for 5 to 10 years.

But if AMD went libre, I'd jump ship.

Re: Safeboot: Booting Linux Safely

#45
post #6

Earlier quoted context omitted.

Isn't that what Bitlocker and Secure Boot do essentially? https://docs.microsoft.com/en-us/windows-hardware/design/dev...

In its typical configuration, Secure Boot can't provide any anti-theft guarantees because an attacker could just replace the contents of the disk with a new Windows installation and the workstation would be usable for them. Secure Boot as it is configured by Windows only prevents malware from inserting itself into the boot process, since all Windows installations use the same signature. Bitlocker only prevents attack…

> In its typical configuration, Secure Boot can't provide any anti-theft guarantees because an attacker could just replace the contents of the disk with a new Windows installation and the workstation would be usable for them.

What's preventing an attacker from resetting the secureboot settings? You'd need some sort of activation scheme like on iOS.

Re: Safeboot: Booting Linux Safely

#46

I really like the philosophical approach here, even if it's too finicky to put in practice today. I'm really sick of everything being made "secure", when in fact the "security" is for someone other than the legitimate user of the thing. Phones, laptops, physical security systems, cars, the list goes on. There was a post here yesterday ( https://news.ycombinator.com/item?id=23149771 ) about the (in)security of Linux,…

"I'm really sick of everything being made "secure", when in fact the "security" is for someone other than the legitimate user of the thing."

There must have been some groundswell movement amongst users all demanding that the boot process be made more "secure". There must have been well-publicised cases where "bad guys" were hijacking the boot process.

Perhaps different people have different definitions of "secure". If some third party, including the seller, has control over access to the computer or what I can run or disable on it after I purchase it, then I do not consider that computer to be more "secure". I just consider it to be less useful and less trustworthy to use with any personal data.

Re: Safeboot: Booting Linux Safely

#47

So what about this: - Copy GRUB, bootlines for your system, your kernel and initrd to a WORM media like a bootable CD-ROM. - Boot using CD-ROM. - When boot completes, remove the CD-ROM. Now you can't attack my boot kernel or boot process because I've just physically separated it from the system and taken it with me. Even if it was there, the media is read only so you can't modify it. If I need to upgrade, I need to b…

My understanding is MicroSD “hardware” switch triggers a software based switch that not enforced by the hardware; that is, it is not designed security.

Even a “read only” CD-ROM if not verified on boot for tampering — might contain an attack, including: to just disable the disk from booting, among other things.

Re: Safeboot: Booting Linux Safely

#48

Earlier quoted context omitted.

> I'm really sick of everything being made "secure", when in fact the "security" is for someone other than the legitimate user of the thing. It's less binary than that for me. Yes, the same technologies that keep my data secure also act as a buttress against jailbreaking. But people who want to jailbreak can simply choose less-secure devices, while I would personally not trade that security for greater hackability. T…

Apparently your threat model doesn't include governments and large corporations, who have done more enumerable harm (e.g. through the military-industrial-information complex) to people than small-time crooks ever have. Sometimes it seems more people want to live in prison (or a gilded cage), than in regular civilian life with all its attendant dangerous freedoms. The point of the OP is that users can and deserve to h…

I appreciate the conversation.

> Apparently your threat model doesn't include governments and large corporations…

It's a consideration for sure, and it's why I use Apple devices instead of Google-powered ones, don't use Facebook, use DuckDuckGo as my primary search engine, etc.

I'm not worried about Apple selling my information (for now, given their current business model) but my network provider is absolutely doing this regardless of device. Given that, what actionable recommendation is even possible?

Re: Safeboot: Booting Linux Safely

#49

Earlier quoted context omitted.

Apparently your threat model doesn't include governments and large corporations, who have done more enumerable harm (e.g. through the military-industrial-information complex) to people than small-time crooks ever have. Sometimes it seems more people want to live in prison (or a gilded cage), than in regular civilian life with all its attendant dangerous freedoms. The point of the OP is that users can and deserve to h…

I appreciate the conversation. > Apparently your threat model doesn't include governments and large corporations… It's a consideration for sure, and it's why I use Apple devices instead of Google-powered ones, don't use Facebook, use DuckDuckGo as my primary search engine, etc. I'm not worried about Apple selling my information (for now, given their current business model) but my network provider is absolutely doing…

VPN?

Re: Safeboot: Booting Linux Safely

#50
post #46

I really like the philosophical approach here, even if it's too finicky to put in practice today. I'm really sick of everything being made "secure", when in fact the "security" is for someone other than the legitimate user of the thing. Phones, laptops, physical security systems, cars, the list goes on. There was a post here yesterday ( https://news.ycombinator.com/item?id=23149771 ) about the (in)security of Linux,…

"I'm really sick of everything being made "secure", when in fact the "security" is for someone other than the legitimate user of the thing." There must have been some groundswell movement amongst users all demanding that the boot process be made more "secure". There must have been well-publicised cases where "bad guys" were hijacking the boot process. Perhaps different people have different definitions of "secure". I…

> There must have been some groundswell movement amongst users all demanding that the boot process be made more "secure".

There wasn't. Users want security in general but most people would not even realize it if a boot process was insecure nor would they understand the implications.

> There must have been well-publicised cases where "bad guys" were hijacking the boot process.

Yes. The "bad" guys are the people running "unauthorized" software on computer hardware. Governments and corporations would very much like to restrict what users can and can't do. Widespread cryptography is viewed as an existential threat to law enforcement and intelligence gathering. Companies enjoy owning their users and being in a monopoly position with regards to the software market for their devices. So we get systems which control the user instead of systems controlled by the user.

Post reply on HN