5 ms·
Ah, I see. It's just another fucking tpm, which let's venders approve or deny execution of signed binaries. So more infrastructure to attack general computing.
by ottah 7mo ago
Ah, I see. It's just another fucking tpm, which let's venders approve or deny execution of signed binaries. So more infrastructure to attack general computing.
- UltraSane 7mo agoNo, TPMs and HSMs are fundamentally nothing more than secure hardware dedicated to storing private keys in a way that makes accessing the plaintext incredibly hard. All of modern computer security is based on them.
- pabs3 7mo ago... and usually deployed in a user-hostile manner.
- UltraSane 7mo agoAny evidence of this? Computer security was a complete disaster before hardware roots of trust became standard.
- NewJazz 7mo agoBoth things can be true.
- UltraSane 7mo agoThe knee-jerk hysterical reaction to any talk of hardware roots of trust on Hacker News is getting tiresome and I expect better given the reputation of the site. It actually reminds me of old slashdot.
- pabs3 7mo agoThe software running on such devices is usually proprietary and never installed by the user. That is user-hostile.
- UltraSane 7mo agoWhat software?
- pabs3 7mo agoThe firmware implementing TPM functionality, which definitely exists in at least some cases: https://en.wikipedia.org/wiki/Trusted_Platform_Module#Field_upgrade https://en.wikipedia.org/wiki/Trusted_Platform_Module#Field_... For ASIC-only devices, the keys are burned-in, which is user-hostile too.
- UltraSane 7mo agoIs the firmware in my NIC user-hostile?
- yencabulator 7mo agoThe firmware in one of my NICs for sure is. The vendor says they're not bothering to fix it, and nobody else is able to. https://www.blackduck.com/blog/cyrc-discovers-asus-tplink-wlan-vulnerabilities.html https://www.blackduck.com/blog/cyrc-discovers-asus-tplink-wl...
- hulitu 7mo ago> Computer security was a complete disaster It is still a complete disaster. Nobody needs the password to your bootloader when it can access all your data through your web browser.
- UltraSane 7mo agoThat isn't possible.