I really like the philosophical approach here, even if it's too finicky to put in practice today. I'm really sick of everything being made "secure", when in fact the "security" is for someone other than the legitimate user of the thing. Phones, laptops, physical security systems, cars, the list goes on. There was a post here yesterday ( https://news.ycombinator.com/item?id=23149771 ) about the (in)security of Linux,…
> I'm really sick of everything being made "secure", when in fact the "security" is for someone other than the legitimate user of the thing. It's less binary than that for me. Yes, the same technologies that keep my data secure also act as a buttress against jailbreaking. But people who want to jailbreak can simply choose less-secure devices, while I would personally not trade that security for greater hackability. T…
Safeboot: Booting Linux Safely
51–60 of 61 posts
Re: Safeboot: Booting Linux Safely
#52https://duo.com/labs/research/secure-boot-in-the-era-of-the-...
Re: Safeboot: Booting Linux Safely
#53I really like the philosophical approach here, even if it's too finicky to put in practice today. I'm really sick of everything being made "secure", when in fact the "security" is for someone other than the legitimate user of the thing. Phones, laptops, physical security systems, cars, the list goes on. There was a post here yesterday ( https://news.ycombinator.com/item?id=23149771 ) about the (in)security of Linux,…
> I'm really sick of everything being made "secure", when in fact the "security" is for someone other than the legitimate user of the thing. It's less binary than that for me. Yes, the same technologies that keep my data secure also act as a buttress against jailbreaking. But people who want to jailbreak can simply choose less-secure devices, while I would personally not trade that security for greater hackability. T…
I think we know the answer, and that is; the attitude towards things like mobile phones being different to that of a laptop; we don't really "own" or phones in the same sense and if shouldn't be that way.
Re: Safeboot: Booting Linux Safely
#54Earlier quoted context omitted.
Apparently your threat model doesn't include governments and large corporations, who have done more enumerable harm (e.g. through the military-industrial-information complex) to people than small-time crooks ever have. Sometimes it seems more people want to live in prison (or a gilded cage), than in regular civilian life with all its attendant dangerous freedoms. The point of the OP is that users can and deserve to h…
I appreciate the conversation. > Apparently your threat model doesn't include governments and large corporations… It's a consideration for sure, and it's why I use Apple devices instead of Google-powered ones, don't use Facebook, use DuckDuckGo as my primary search engine, etc. I'm not worried about Apple selling my information (for now, given their current business model) but my network provider is absolutely doing…
Personally, I'm looking forward to a pinephone. I'm moving towards asynchronous communications, and leaving my phone at home, or in a "faraday pouch" (made of [0]) on airplane mode.
Networking is done through an elastic ip vpn that forwards to a known host, so web sites that I want to use, but I don't want to trigger the captchas and 3FA stuff, see the same user-agent and IP address. I also have many "disposable" phones, that I use on projects that require Google Hangouts or WeChat. Recently I had to upgrade my daily driver phone, and I haven't installed Lineage yet. It's a slog, so I can totally understand why people would simply accept what's readily on offer.
At a basic level, my thinking is that "is this better for me?". That is, how are these capabilities[1] going to be used, in my favour, or against me? Since I have previously been dragged into a large investigation (regarding someone else operating under a false identity), and have had to get various clearances from various governments to work on projects (which is more common than I would naively think), the approach that I take is to appear unremarkable.
In the past, when leaving countries that require exit visas (like China, Israel), I was shocked at how much information they had on me, and revealed in the course of the exit interview. But I have to assume that Anglo countries, if anything, have more advanced technical means at their disposal, but decline to use them unless the target is juicy enough. So the reasonable approach is to do my best to make my pattern "normal" and "unappealing" -- maximizing my benefit from these tools, and minimizing the risks of false associations and accusations.
[0] https://www.sparkfun.com/products/retired/10056
[1] https://www.theverge.com/2013/8/1/4580718/fbi-can-remotely-a...
Re: Safeboot: Booting Linux Safely
#55Earlier quoted context omitted.
"I'm really sick of everything being made "secure", when in fact the "security" is for someone other than the legitimate user of the thing." There must have been some groundswell movement amongst users all demanding that the boot process be made more "secure". There must have been well-publicised cases where "bad guys" were hijacking the boot process. Perhaps different people have different definitions of "secure". I…
> There must have been some groundswell movement amongst users all demanding that the boot process be made more "secure". There wasn't. Users want security in general but most people would not even realize it if a boot process was insecure nor would they understand the implications. > There must have been well-publicised cases where "bad guys" were hijacking the boot process. Yes. The "bad" guys are the people runnin…
When I was a kid, I used to wonder what the difference was between soldiers and police. I was told that soldiers were meant to protect the State from its enemies, whereas police were meant to enforce the rule of law. I was also told that when soldiers were used for policing, everyone tends to turn into an enemy of the State.
It turns out, this view is correct, but omits that police tend to become soldiers for the State anyway. The ones that actively serve the citizenry's best interests seem to be far and few between.
Re: Safeboot: Booting Linux Safely
#56Earlier quoted context omitted.
> There must have been some groundswell movement amongst users all demanding that the boot process be made more "secure". There wasn't. Users want security in general but most people would not even realize it if a boot process was insecure nor would they understand the implications. > There must have been well-publicised cases where "bad guys" were hijacking the boot process. Yes. The "bad" guys are the people runnin…
This is a great analysis. When I was a kid, I used to wonder what the difference was between soldiers and police. I was told that soldiers were meant to protect the State from its enemies, whereas police were meant to enforce the rule of law. I was also told that when soldiers were used for policing, everyone tends to turn into an enemy of the State. It turns out, this view is correct, but omits that police tend to b…
Re: Safeboot: Booting Linux Safely
#57Earlier quoted context omitted.
This is a great analysis. When I was a kid, I used to wonder what the difference was between soldiers and police. I was told that soldiers were meant to protect the State from its enemies, whereas police were meant to enforce the rule of law. I was also told that when soldiers were used for policing, everyone tends to turn into an enemy of the State. It turns out, this view is correct, but omits that police tend to b…
There isn't that much difference when it comes down to it. https://en.wikipedia.org/wiki/Military_police
In theory, "military police" enforce military law and are responsible for policing the army, navy, and so on. They're usually limited in their ability to enforce civilian law. In the USA, it's prohibited under the Posse Comitatus Act and the Insurrection Act, but this isn't universal by any means.
Re: Safeboot: Booting Linux Safely
#58Earlier quoted context omitted.
Hmmm. This implies that you have set your boot order to CD-ROM first, so anyone can - say - boot their own system on your machine from CD and either access your data or make a dd-copy of your disk and look at it later. You need also to password protect your BIOS so that first device in boot order is hard disk and settings cannot be changed (without BIOS password). Depending on the BIOS this change in booting order co…
I’m guessing this setup makes sense with encrypted disk, that way, since decryption keys are on the CD, you can’t access the files without it.
Since I have a physical trusted copy of that initrd with the kernel and bootloader that is safe.
DD-ing the whole drive is something I assumed Secure Boot doesn't protect as someone could remove the drive and do the same. Even if the drive, eMMC or flash is soldered to the board there's some way to get to it (desolder, JTAG pins, etc.)
Re: Safeboot: Booting Linux Safely
#59If every Linux user would boycott AMD to release their source, then we could have libreboot: https://libreboot.org/amd-libre.html ME vs PSP isn't much of a choice. Of course POWER might be an option eventually, but isn't for most of us currently.
But if they release everything libreboot want's wouldn't that potentially undermine DRM (e.g. webdrm pluging as used by netflix)? I mean I'm not a fan of DRM but then undermining it might cause browsers on Ryzen to no longer be able to run Netflix and similar. While I guess many people on this site wouldn't care too much it's not profitable for AMD. But then there should be a way to have both. The case which don't ne…
Re: Safeboot: Booting Linux Safely
#60Earlier quoted context omitted.
I don't understand. Intel has ME, AMD has PSP, neither makes any particular effort to support libreboot (although I'm pretty sure coreboot can work with both if the manufacturer wants, because Chromebooks do that). Unless you believe that Intel is more open, why would you prefer it? It appears to me that they're equally security-unfriendly, but with AMD at least winning on price and performance.
> It appears to me that they're equally security-unfriendly, but with AMD at least winning on price and performance. I agree (although I'm not sure price and performance is significant enough to matter to me), the only reason I would go with Intel is that it's what I've been using for the last 20 years, and it's what I know. I had an AMD one time (late 90s/early 00s) and had a lot of problems with it. I know AMD toda…