6 ms·
Secure Boot is the computing antichrist, and Linux folk were 100% right to rally against it. As well as a whole bunch of other "Trusted Computing" garbage.
by ACCount36 1y ago
Secure Boot is the computing antichrist, and Linux folk were 100% right to rally against it. As well as a whole bunch of other "Trusted Computing" garbage.
- froh 1y agomind to elaborate? I'd love to know if my machine has been compromised with early boot stage "meta-hypervisor" or not. the promise of secure boot and trusted computing is backdoor-free boot. what is in your eyes evil and garbage about that?
- ACCount36 1y agoWho controls the fucking certs? "My computer was compromised with an early boot stage hypervisor backdoor" happens basically never. It's an attack vector that exists almost entirely in the minds of infosec fucktards. "My brand new device ships with vendor-selected boot certificates that can't be changed, can't be overridden, and control what software I can install onto my own device" happens with every other smartphone, gaming console, car, and even some PCs. "Trusted Computing" is, and always was, about making sure that the user doesn't actually own his device. This is the real, tangible attack vector - and the target of this attack is user freedom and choice.
- flexagoon 1y ago> Who controls the fucking certs? Cert authorities, just like in case of SSL. Is SSL also an evil technology designed to take away freedom from the internet? > vendor-selected boot certificates that can't be changed That's a lie. Certain drivers are signed with a specific key, and they can only be used when this key is installed, which makes sense. The same thing happens with SSL - if you remove pre-installed CA certs from your device, HTTPS sites will stop working. However, nothing is stopping you from adding your own keys to the system and signing your own software with it. > happens with every other smartphone, gaming console, car, and even some PCs How often are you trying to install custom drivers on a smartphone, console or car? Why would you have secure boot issues on those? > the target of this attack is user freedom and choice. Which is exactly why users have the freedom and choice to just disable Secure Boot?
- ACCount36 1y agoTake an iPhone or a Switch. Then disable Secure Boot on it. Good fucking luck. The reason why Apple or Nintendo go out of their way to make this impossible isn't user security. It's the "security" of their 30% App Store cut. Out in the wild, Secure Boot exists to "secure" vendor revenue streams - and PCs are the only devices where it's even possible for the user to disable it. Most of the time. What's happening in smartphone space is enough of a reason to treat Secure Boot on PC like an ongoing attack. The only reason why there are still legitimate ways to disable or adjust it is that most PC manufacturers don't have their own app store.
- tempnew 1y agoFreedom vs safety should be contextual. I’m not free if I don’t have choices and secure boot is a choice. Having it improves both my freedom and security somewhat. I want both unlocked and locked hardware, for different purposes.
- ACCount36 1y agoSecure Boot is almost never a choice. It's just something a hardware vendor hits you with, whether you like it or not.
- tempnew 1y agoIt’s a choice I make all the time. I disabled it on one of my computers just last night. I’ll probably turn it back on today. It’s easy to toggle.
- ACCount36 1y agoNow do that on your smartphone. And then on your smart watch. And then on your gaming console. Secure Boot being "a choice" on PC is an exception, not the norm. On just about every other device, the vendor is going to take a boot, shove it up your ass, and say "it's there to make your ass more secure" if you complain.
- preisschild 1y ago> Who controls the fucking certs? You can? Delete the default (ie Windows certs) and import your own.
- m4rtink 1y agoI think it is only required on x86 EFI machines due to some old antitrust rulings. Provided the firmware vendor actually implements it right. On ARM for example the hardware, including some hardware shipping with ARM version of Windows, does not need to provide the option to add custom certs and remove existing ones, so AFAIK in most cases it is not possible.
- preisschild 1y agoI think you can do the same in the Tianocore EDK2 ARM UEFI But yeah, many ARM boards don't use open UEFI firmware
- gsich 1y agoI do.
- h4ck_th3_pl4n3t 1y agoLol you never read about all the Lenovo malware fuckups, apparently. Which basically are exactly what "infosec fucktards" as you named them warned about.
- fsflover 1y agoConsider using Heads with TPM and Librem Key to detect possible compromise of your boot stage. It doesn't obey MS but you.
- flexagoon 1y agoWith Heads, the firmware measures itself and sends the results to the TPM. If an attacker flashes a modified firmware that simply lies about the measurement results, the entire security system will be bypassed.
- fsflover 1y agoThis is not true: https://forum.qubes-os.org/t/discussion-on-purism/2627/187 https://forum.qubes-os.org/t/discussion-on-purism/2627/187 https://forum.qubes-os.org/t/discussion-on-purism/2627/177 https://forum.qubes-os.org/t/discussion-on-purism/2627/177
- froh 1y agothat's still secure boot, isn't it? just not uefi but homegrown? fine with me. I read GP as rejecting the whole idea. to point at another elephant in the room: at some point I came to realize that the ME is a x468 running some BSD. that little bitch has full access to your machine. if trust and security is the objective, we're in for a hard ride to find trustworthy hardware.
- fsflover 1y agoME is disabled and neutralized on my Librem 15: https://puri.sm/learn/intel-me/ https://puri.sm/learn/intel-me/
- zozbot234 1y ago> I'd love to know if my machine has been compromised with early boot stage "meta-hypervisor" or not. Boot from read-only media you control, or set up network boot from a source you trust - you have to trust the firmware anyway. Secure Boot itself is quite pointless.
- fsflover 1y ago> you have to trust the firmware anyway If it's FLOSS wirh reproducible builds, your trust can be minimized, since the community verification is going on constantly. Also, your suggestion is quite inconvenient and cumbersome to use and set up.
- FuriouslyAdrift 1y agoNow do Systemd...
- drowsspa 1y agoYeah, it opened up the door for us not owning not even our phones anymore, and soon even the browser itself.
- rurban 1y agoTrusted Computing is to trust the NSA with your computing. They need to have access, right? And since they cannot control all hardware vendors, they opted to control Microsoft instead, and forced UNIX to play ball.