6 ms·
I don't know about executable signing, but in the embedded world SecureBoot is also used to serve the customer; id est provide guarantees to the customer that t
by astrobe_ 6mo ago
I don't know about executable signing, but in the embedded world SecureBoot is also used to serve the customer; id est provide guarantees to the customer that the firmware of the device they receive has not been tampered with at some point in the supply chain.
- 201984 6mo agoAnd what if that customer wants to run their own firmware, ie after the manufacturer goes out of business? "Security" in this case conveniently prevente that.
- gjsman-1000 6mo agoTradeoffs. Which is more likely here? 1. A customer wants to run their own firmware, or 2. Someone malicious close to the customer, an angry ex, tampers with their device, and uses the lack of Secure Boot to modify the OS to hide all trace of a tracker's existence, or 3. A malicious piece of firmware uses the lack of Secure Boot to modify the boot partition to ensure the malware loads before the OS, thereby permanently disabling all ability for the system to repair itself from within itself Apple uses #2 and #3 in their own arguments. If your Mac gets hacked, that's bad. If your iPhone gets hacked, that's your life, and your precise location, at all times.
- samlinnfer 6mo ago1. P(someone wants to run their own firmware) 2. P(someone wants to run their own firmware) * P(this person is malicious) * P(this person implants this firmware on someone else’s computer) 3. The firmware doesn’t install itself Yeah I think 2 and 3 is vastly less likely and strictly lower than 1.
- gjsman-1000 6mo agoOn Android, according to the Coalition Against Stalkerware, there are over 1 million victims of deliberately placed spyware on an unlocked device by a malicious user close to the victim every year. #2 is WAY more likely than #1. And that's on Android which still has some protections even with a sideloaded APK (deeply nested, but still detectable if you look at the right settings panels). As for #3; the point is that it's a virus. You start with a webkit bug, you get into kernel from there (sometimes happens); but this time, instead of a software update fixing it, your device is owned forever. Literally cannot be trusted again without a full DFU wipe.
- samlinnfer 6mo agoAnd where are the stats for people running their own firmware and are not running stalkerware for comparison? You don’t need firmware access to install malware on Android, so how many of stalkerware victims actually would have been saved by a locked bootloader?
- gjsman-1000 6mo agoThe entirety of GrapheneOS is about 200K downloads per update. Malicious use therefore is roughly 5-1. > You don’t need firmware access to install malware on Android, so how many of stalkerware victims actually would have been saved by a locked bootloader? With a locked bootloader, the underlying OS is intact, meaning that the privileges of the spyware (if you look in the right settings panel) can easily be detected, revoked, and removed. If the OS could be tampered with, you bet your wallet the spyware would immediately patch the settings system, and the OS as a whole, to hide all traces.
- kuschku 6mo agoLineageOS alone has around 4 million active users. So malicious use is at most 1:4, not 5:1.
- samlinnfer 6mo agoAssuming that we accept your premise that the most popular custom firmware for Android is stalkerware (I don’t). This is of course, a firmware level malware, which of course acts as a rootkit and is fully undetectable. How did the coalition against stalkerware, pray tell, manage to detect such an undetectable firmware level rootkit on over 1 million Android devices?
- Zak 6mo agoThis assumes a high level of technical skill and effort on the part of the stalkerware author, and ignores the unlocked bootloader scare screen most devices display. If someone brought me a device they suspected was compromised and it had an unlocked bootloader and they didn't know what an unlocked bootloader, custom ROM, or root was, I'd assume a high probability the OS is malicious.
- philistine 6mo agoAs if the monetary gain of 2 and 3 never entered the picture. Malicious actors want 2 and 3 to make money off you! No one can make reasonable amounts of money off 1.
- itsdesmond 6mo agoThis guy thinks that if you rephrase an argument but put some symbols around it you’ve refuted it statistically. P(robably not)
- samlinnfer 6mo agoThe argument is that P(customer wants to run their own firmware) cancels out and 2,3 are just the raw probability of you on the receiving end of an evil maid attack. If you think this is a high probability, a locked bootloader won’t save you.
- FabHK 6mo agoVery neat, but 1) is not really P(customer wants to run their own firmware), but P(customer wants to run their own firmware on their own device). So, the first term in 1) and 2) are NOT the same, and it is quite conceivable that the probability of 2) is indeed higher than the one in 1) (which your pseudo-statistical argument aimed to refute, unsuccessfully).
- lazide 6mo agoClearly you’ve never met my ex’s (or a past employer). Not even being sarcastic this time.
- mikestew 6mo agoAs an embedded programmer in my former life, the number of customers that had the capability of running their own firmware, let alone the number that actually would, rapidly approaches zero. Like it or not, what customers bought was an appliance, not a general purpose computer. (Even if, in some cases, it as just a custom-built SBC running BusyBox, customers still aren't going to go digging through a custom network stack).
- account42 6mo agoThe customers don't have to install the firmware themselves, they can have a friend do it or pay a repair shop. You know, just like they can with non-computerized tools that they don't fully understand.
- mikestew 6mo agoI’m not talking about your buddy’s Android phone, the context was embedded systems with firmware you’re not going to find on xda developers. A “friend” isn’t going to know jack shit about installing firmware on an industrial control.
- the__alchemist 6mo agoI encourage you to re-evaluate this. How many devices do you (or have you) own which have have a microcontroller? (This includes all your appliances, your clocks, and many things you own which use electricity.) How many of these have you reflashed with custom firmware? Imagine any of your friends, family, or colleagues. (Including some non-programmers/hackers/embedded-engineers) What would their answers be?
- account42 6mo agoI would reflash almost all my appliances if I could do so easily since they all come with non-optimal behavior for me.
- dns_snek 6mo ago#2 and #3 are fearmongering arguments and total horseshit, excuse the strong language. Should either of those things happen the bootloader puts up a big bright flashing yellow warning screen saying "Someone hacked your device!" I use a Pixel device and run GrapheneOS, the bootloader always pauses for ~5 seconds to warn me that the OS is not official.
- root_axis 6mo agoYes. They're making the point that your flashing yellow warning is a good thing, and that it's helpful to the customer that a mechanism is in place to prevent it from being disabled by an attacker.
- dns_snek 6mo agoNo, they've presented a nonsense argument which Apple uses to ban all unofficial software and firmware as if it had some merit.
- account42 6mo ago> 2. Someone malicious close to the customer, an angry ex, tampers with their device, and uses the lack of Secure Boot to modify the OS to hide all trace of a tracker's existence, or Lol security people are out of their mind if they think that's actually a relevant concern. > 3. A malicious piece of firmware uses the lack of Secure Boot to modify the boot partition to ensure the malware loads before the OS, thereby permanently disabling all ability for the system to repair itself from within itself Oh no so now the malware can only permanently encrypt all the users files and permanently leak their secrets. But hey at least the user can repair the operating system instead of having to reinstall it. And in practice they can't even be sure about that because computers are simply too complex.
- deleted 6mo ago[deleted]
- hhh 6mo agoyou click the box to turn off secure boot
- bakugo 6mo ago...and then some essential software you need to run detects that and refuses to run. See where the problem is here?
- bigfatkitten 6mo agoIt does no such thing if you enrol your own keys using the extremely well documented process to do that.
- greycol 6mo agoIt's fair to think of secure boot in only the PC context but the model very much extends to phones. It seems ridiculous to me that to use a coupon for a big mac I have to compromise on what features my phone can run (either by turning on secure boot and limiting myself to stock os or limiting myself to the features and pricing of the 1 or 2 phones that allow re-locking).
- account42 6mo agoAnd the PC situation is only a leftover due to historical circumstances that will be "corrected" in due time. Microsoft already tried this once with their ARM devices.
- 201984 6mo agoWhere is this "extremely well documented process" to enroll new signing keys on an embedded device? I don't see one for any of these embedded processors with secure boot. https://pip-assets.raspberrypi.com/categories/1214-rp2350/documents/RP-008373-DS-2-rp2350-datasheet.pdf?disposition=inline https://pip-assets.raspberrypi.com/categories/1214-rp2350/do... https://documentation.espressif.com/esp32_technical_reference_manual_en.pdf https://documentation.espressif.com/esp32_technical_referenc... https://docs.amd.com/v/u/en-US/ug1085-zynq-ultrascale-trm https://docs.amd.com/v/u/en-US/ug1085-zynq-ultrascale-trm
- jmye 6mo agoThen that customer shouldn't buy a device that doesn't allow for their use case. Exercise some personal agency. Sheesh.
- bakugo 6mo agoWhat happens when there are no more devices that allow for that use case? This is already pretty much the case for phones, it's only a matter of time until Microsoft catches up.
- astrobe_ 6mo agoWell, that's a different market. What I say is that there are markets in which customers wants to be sure that the firmware is from "us". And those markets are certainly not IoT gizmos, which I suspect induce some knee-jerk reactions and I understand that cause I'm a consumer too. But big/serious customers actually look at the wealthiness of the company they buy from, and would certainly consider running their own firmware on someone else's product; they buy off-the-shelf products because it's not their domain of expertise (software development and/or whatever the device does), most of the times.
- deleted 6mo ago[deleted]
- tosti 6mo agoComputers should abide by their owners. Any computer not doing that is broken.
- cferry 6mo agoI make the analogy with a company, because on that front, ownership seems to matter a lot in the Western world. It's like it had to have unfaithful management appointed by another company they're a customer of, as a condition to use their products. Worse, said provider is also a provider for every other business, and their products are not interoperable. How long before courts jump in to prevent this and give back control to the business owner?
- wat10000 6mo agoThis gets tricky. If I click on a link intending to view a picture of a cat, but instead it installs ransomware, is that abiding by its owner or not? It did what I told it to do, but not at all what I wanted.
- ghighi7878 6mo agoWe dont need to get philosophical here. You(the admin) can require you (the user) to input a password to signify to you(the admin) to install a ransomware when a link is clicked. That way no control is lost.
- wat10000 6mo agoWhat if the cat pictures are an app too? The computer can't require a password specifically for ransomware, just for software in general. The UI flow for cat pictures apps and ransomware will be identical.
- Zak 6mo agoA computer that can run arbitrary programs can necessarily run malicious ones. Useful operations are often dangerous, and a completely safe computer isn't very useful. Some sandboxing and a little friction to reduce mistakes is usually wise, but a general-purpose computer that can't be broken through sufficiently determined misuse by its owner is broken as designed.
- mort96 6mo agoIt's to serve the regulators. The Radio Equipment Directive essentially requires the use of secure boot fir new devices.
- petcat 6mo agoI happen to like knowing that my mobile device did not have a ring 0 backdoor installed before it left the factory in Asia. SecureBoot gives me that confidence.
- mort96 6mo agoNo it doesn't? The factory programs in the secure boot public keys
- petcat 6mo agoThe public keys are provided by the developer. Google, or Apple, for example. It's how they know that nothing was tampered with before it left the factory.
- realusername 6mo agoNothing has been tampered with doesn't mean there's no factory backdoor, it just only means same as factory, nothing more.
- petcat 6mo agoApple or Google know what the cryptographic signature of the boot should be. They provide the keys. It's how they know that "factory reset" does not include covert code installed by the factory. That's what we're talking about.
- mort96 6mo agoThis is true for phones but not for IoT in general.
- Galanwe 6mo ago> id est provide guarantees to the customer that the firmware of the device they receive has not been tampered with The firmware of the device being a binary blob for the most part... Not like I trust it to begin with. Whereas my open source Linux distribution requires me to disables SecureBoot. What a world.
- repelsteeltje 6mo ago+1 An unsigned hash is plenty guard to against tampering. The supply chain and any secret sauce that went into that firmware is just trust. Trust that the blob is well intentioned, trust that you downloaded from the right URL, checked the right SHA, trust that the organization running the URL is sanctioned to do so by Microsoft... Once all of that trust for every piece of software is concentrated in one organization, Microsoft, Apple or Google, is has become totally meaningless.
- WhyNotHugo 6mo agoYou can set up custom SecureBoot keys on your firmware and configure Linux to boot using it. There's also plenty of folks combining this with TPM and boot measurements. The ugly part of SecureBoot is that all hardware comes with MS's keys, and lots of software assume that you'll want MS in charge of your hardware security, but SecureBoot _can_ be used to serve the user. Obviously there's hardware that's the exception to this, and I totally share your dislike of it.
- Galanwe 6mo ago> You can set up custom SecureBoot keys on your firmware and configure Linux to boot using it. Right, but as engineers, we should resist the temptation to equate _possible_ with _practical_. The mere fact that even the most business oriented Linux distributions have issues playing along SecureBoot is worrying. Essentially, SB has become a Windows only technology. The promise of what SB could be useful for is even muddier. I would argue that the chances of being victim of firmware tampering are pretty thin compared to other attack vectors, yet somehow we end up all having SB and its most significant achievement is training people that disabling it is totally fine.
- PunchyHamster 6mo agowell, unless govt tells MS to tamper it
- burstmode 6mo agoI don't know about executable signing, but in the embedded world SecureBoot is also used to serve the PRODUCER; id est provide guarantees to the PRODUCER that the firmware of the device they SELL has not been tampered with at some point in the PROFIT chain.
- deleted 6mo ago[deleted]
- astrobe_ 6mo agoFrankly: that's stupid. In case you didn't figure it out, I work in the field and I can tell you that this is was not the mindset at the places where I worked.
- rurban 6mo agoIn my case a firmware provider went out of business, and in one particular device the firmware gets stuck in an endless boot loop. It tries to calibrate some led's, but forgets to round some differences, so it can never converge to a proper calibration. Device is bricked, firmware is secured with a signing key, refactoring a new device is pretty hard. The current one needed 10 years of development. I'm on the wait to either patch the firmware by finding the problematic byte (if it's patchable, round() needs much more), or to wait for the original dev willing to release an update on his own. BTW Claude opus got much better than ghidra lately. It's perfect. I see the value of protected firmware updates, but business has to survive also.