5 ms·
> I don't see why a signed bootloader starting a signed attestation engine wouldn't be trusted by third party websites. Do you mean a kind of Linux where root
by codedokode 3y ago
> I don't see why a signed bootloader starting a signed attestation engine wouldn't be trusted by third party websites.
Do you mean a kind of Linux where root cannot do anything he wants? Like Android?
- jeroenhd 3y agoYes, a kind of Linux like Ubuntu or Fedora that already boots with secure boot enabled with full support of TPMs and similar technologies. The kind of Linux 99% of Linux users are running today. More secure variants like Android, leveraging SELinux and such, help with sandboxing but I don't think that SELinux is a struct requirement.
- raxxorraxor 3y agoThey are not more secure at all.
- codedokode 3y agoI mean if root can do anything then such system is not "trusted" from corporations point of view. Therefore, it won't be able to pass the attestation or play DRM content.
- hollerith 3y agoHuh? Fedora defaults to secure boot's being off and it is complicated to get it turned on. Even after you manage to turn it on, it only verifies the kernel and cannot do anything about malware hiding in /usr. There is no Linux distro AFIAK that has verification of the entire system like ChromeOS, MacOS, iOS, Android and Windows have.
- jeroenhd 3y agoFedora's own website [1] states: > Fedora includes support for the UEFI Secure Boot feature, which means that Fedora can be installed and run on systems where UEFI Secure Boot is enabled. On UEFI-based systems with the Secure Boot technology enabled, all drivers that are loaded must be signed with a valid certificate, otherwise the system will not accept them. All drivers provided by Red Hat are signed by the UEFI CA certificate. Running your own secure boot CA is not enabled out of the box (for obvious reasons), but that does not pose a problem on most systems. Secure boot only needs special care if you need to load unsigned kernel modules (DKMS, Nvidia) or if you run on a super duper special Microsoft device that doesn't have the third party CA certificate by default. [1]: https://docs.fedoraproject.org/en-US/fedora/latest/system-administrators-guide/kernel-module-driver-configuration/Working_with_the_GRUB_2_Boot_Loader/#sec-UEFI_Secure_Boot https://docs.fedoraproject.org/en-US/fedora/latest/system-ad...
- hollerith 3y agoNothing you wrote contradicts anything I wrote. Specifically, although Fedora support secure boot, if you follow the standard install process, you will get a system with secure boot turned off. I know because I've installed Fedora on a system capable of secure boot. And, again, it is complicated to get it turned on. How complicated? Take a look: https://nwildner.com/posts/2021-04-10-secureboot-fedora/ https://nwildner.com/posts/2021-04-10-secureboot-fedora/ >The kind of Linux 99% of Linux users are running today. I severely doubt that even 5% of Linux installs have secure boot turned on because of how complicated it is to get it working. Specifically I imagine that the complicated instructions on the page I just linked will need to be modified depending on the specific secure-boot firmware.
- jeroenhd 3y ago> Earlier I wrote, "it is complicated to get it turned on". How complicated? Take a look: > https://nwildner.com/posts/2021-04-10-secureboot-fedora/ https://nwildner.com/posts/2021-04-10-secureboot-fedora/ Most motherboards ship with secure boot enabled out of the box. Fedora will install and boot in that configuration without any changes to your system or motherboard settings. You actually have to go out of your way to disable it. The manual (https://docs.fedoraproject.org/en-US/fedora/f36/install-guide/install/Booting_the_Installation/ https://docs.fedoraproject.org/en-US/fedora/f36/install-guid...) does not mention any such setting changes. The page you link goes into custom secure boot keys, which are usually unnecessary. They're arguably more secure, but it's an entirely optional step unless you decide to load unsigned kernel modules.
- hollerith 3y agoIf secure boot is enabled on the motherboard, Fedora can be installed and used without going into the motherboard firmware and turning it off, but that is different from secure boot's providing to the Fedora install the kind of security assurances that secure boot provides to the other mainstream operating systems (Windows, MacOS, iOS, Android and ChromeOS). For instance, initrd is not verified: https://news.ycombinator.com/item?id=36717975 https://news.ycombinator.com/item?id=36717975 >The page you link goes into custom secure boot keys, which are usually unnecessary. You might be right about that.