3 ms·
Verifiable to who? Some remote third party that isn't me? The hell would I want that?
by dTal 9mo ago
Verifiable to who? Some remote third party that isn't me? The hell would I want that?
- murphyslaw 9mo agoJust an assumption here, but the project appears to be about the methodology to verify the install. Who holds the keys is an entirely different matter.
- dsr_ 9mo agoWerner Von Braun only built the rockets; he didn't aim them, nor did he care where they landed. (London. On some of my relatives.)
- daviddever23box 9mo ago...and the moon.
- dsr_ 9mo agoYou'll understand if I don't think the tradeoffs were necessary, or worthwhile.
- jacquesm 9mo agoAmbition does really weird things to people. But I'm sure in this case when they achieve some kind of dominant position and Microsoft offers to re-absorb them they will do the honorable thing.
- direwolf20 9mo agoWhen has that ever happened in the entire human history?
- mrguyorama 9mo agoPeople do the honorable thing all the time. These people don't, but people you've never heard of are always doing honorable things. Might be some sort of connection there.
- Spivak 9mo agohttps://0pointer.net/blog/authenticated-boot-and-disk-encryption-on-linux.html https://0pointer.net/blog/authenticated-boot-and-disk-encryp... You. The money quote about the current state of Linux security: > In fact, right now, your data is probably more secure if stored on current ChromeOS, Android, Windows or MacOS devices, than it is on typical Linux distributions. Say what you want about systemd the project but they're the only ones moving foundational Linux security forward, no one else even has the ambition to try. The hardening tools they've brought to Linux are so far ahead of everything else it's not even funny.
- direwolf20 9mo agoThis is basically propaganda for the war on general purpose computing. My user data is less safe on a Windows device, because Microsoft has full access to that device and they are extremely untrustworthy. On my Linux device, I choose the software to install.
- Spivak 9mo agoWhat are you talking about? This has nothing to do with general purpose computing and everything to do with allowing you to authenticate the parts of the Linux boot process that must by necessity be left unencrypted in order to actually boot your computer. This is putting SecureBoot and the TPM to work for your benefit. It's not propaganda in any sense, it's recognizing that Linux is behind the state of the art compared to Windows/macOS when it comes to preventing tampering with your OS install. It's not saying you should use Windows, it's saying we should improve the Linux boot process to be a tight security-wise as the Windows boot process along with a long explanation of how we get there.
- direwolf20 9mo agoSecure boot is initialized by the first person who physically touches the computer and wants to initialize it. Guess who that is? Hint: it's not the final owner. It's only secure from evil maker attacks if it can be wiped and reinitialised at any time.