3 ms·
My only fear is that every vendor will now have to implement secure boot and other mechanisms in order to make sure that only signed software runs on their devi
by chme 2y ago
My only fear is that every vendor will now have to implement secure boot and other mechanisms in order to make sure that only signed software runs on their devices, while providing no way for the customer to take ownership of the device back, so that they can run their own software.
I really hope that we eventually get a mandate so that every device, that requires an internet connection for any and all features, will also have to allow the customer to overwrite and use their own software in case they have to make any software/security repairs themselves.
- Borg3 2y agoPanic NOT :) There is still retro computing move...
- transpute 2y agoWhy not both? Build an open future on the expensive lessons of past hardware.
- chme 2y agoYeah, I plan on trying to keep my existing stuff, that allows me to put my own software on it, alive as long as possible. But it would be sad if I could no longer just buy a new off-the-shelf router and install OpenWrt on it.
- Borg3 2y agoYeah, I hope it wont happen like this. Unfortunately, Im kinda pesymistic on this one :(
- transpute 2y agoStrict launch integrity (unlike "secure boot") depends on a customer-defined root of trust. OpenCompute (OCP) Caliptra is an effort by hyperscalers to enforce a platform root of trust with OSS firmware, mandating dual signature by server OEM and hyperscaler customer. The platform RoT is responsible for validating device firmware and OS boot. https://www.youtube.com/watch?v=p9PlCm4tLb8&t=2764s https://www.youtube.com/watch?v=p9PlCm4tLb8&t=2764s > Often we see.. great security.. compromised by other great ideas for mgmt and other things.. starts to weaken its security posture.. want to keep Caliptra very clean [via OSS firmware transparency] Separately, AMD has promised OpenSIL open firmware by 2026, https://www.phoronix.com/news/AMD-openSIL-Detailed https://www.phoronix.com/news/AMD-openSIL-Detailed Isolation architectures like pKVM on Android can run banking or wallet applications in a security-controlled VM, alongside arbitrary user-defined VMs. In contested environments, both security and the freedom to innovate are necessary to survive an arms race with a competent adversary.
- chme 2y agoPersonally, I have more trust in open source software than anything the vendor puts on their devices. But very often either the vendor software is only allowed to run, or you have to disable secure boot to run your own software, weakening your security. So I would like to have a process where the actual end-user and owner of the device is the root of trust, and then transfer that trust to the vendor software or to their own software if they so choose, instead of having the manufacture, vendor or some agency be the root of trust. Of course, it can come with a sensible setup, where the vendor is already trusted, but that trust should always be revokable. There should also be a way to remove or transfer the ownership to another person, if the device is sold. IIUC, OpenTitan is implementing this: https://opentitan.org/book/doc/security/specs/index.html https://opentitan.org/book/doc/security/specs/index.html pKVM goes in a different direction, where software that is run, does not trust the host system, which IMO is not very nice. Trust is something that goes both ways and need to be earned, if I put trust in a software and install it on my system, then I assume that the software also trusts me. If the software doesn't trust me, why should I trust it? If there is no trust between us, then it should not run on my system but on someone elses and let me communicate with it via a well-defined API we can both trust.