5 ms·
Furious searches for BIOS only era hardware are taking place on ebay as we speak. To use with a modified Linux kernel that emulates a bog standard Thinkpad uef
by tepitoperrito 4y ago
Furious searches for BIOS only era hardware are taking place on ebay as we speak.
To use with a modified Linux kernel that emulates a bog standard Thinkpad uefi environment of course.
EDIT: I forgot to phrase this as a question - besides missing a QubesOS or KickSecure on top, is this a decent plan for airgapped stuff?
- justsomehnguy 4y agoJust run your OS in a VM.
- sitzkrieg 4y agowhat should you run the vm on?
- dboreham 4y agoA turtle.
- justsomehnguy 4y agoOn a trusty prehistoric hardware obtained in Brown Sector.
- Arnavion 4y agoI'm not sure what you mean by "a modified Linux kernel that emulates a bog standard Thinkpad uefi environment". The UEFI environment is provided by the firmware and starts EFI applications, which could be a UKI containing your kernel+initramfs, or grub that then starts your kernel+initramfs from /boot, or anything else. ie the UEFI sits below the kernel. UEFI can be emulated on top of BIOS using something like Clover. But for your BIOS-only mobo, just keep using it with a BIOS-only bootloader, ie GPT disk with grub or whatever written to the MBR + BIOS Boot partition. There's no reason to involve any UEFI, emulated or otherwise. You will obviously not have as good protection from evil maid attacks as you would've gotten from Secure Boot. But presumably you're okay with that, and emulated UEFI will not help in that regard anyway.
- zekica 4y agoUEFI Secure Boot doesn't completely protect against physical attacks. If a person can turn off and turn on the computer, they can replace the currently active UEFI bootloader with a shim app, enroll their own key. They can then run any UEFI binary, that binary can then do whatever, and at the end remove the SHIM NVRAM variable that it used, finally loading the original OS bootloader and removing all traces.
- Arnavion 4y ago>UEFI Secure Boot doesn't completely protect against physical attacks. I didn't say it did. In fact I formulated what I wrote precisely to convey the opposite message. >they can replace the currently active UEFI bootloader with a shim app, enroll their own key. UEFI can be protected by a password if the implementation supports it. How secure that is is of course up to the implementation.
- lmm 4y agoPresumably the point is to run something that assumes/relies on UEFI (an OS or application) without having to run and trust the giant blob of low-quality code that is a typical hardware UEFI implementation.
- Arnavion 4y agoSure, but we know that the OS they're asking about is Linux, and none of the major Linux distros require UEFI to boot.
- lmm 4y agoI understood them to be talking about using Linux as the hypervisor that would emulate a UEFI environment, the guest OS might be something different.
- tepitoperrito 4y agoYup.