6 ms·
In my opinion it isn't a bad thing because in the future, when Microsoft disallows disabling secure boot, using BIOS vulnerabilities will be the only way to ins
by paralelogram 12y ago
In my opinion it isn't a bad thing because in the future, when Microsoft disallows disabling secure boot, using BIOS vulnerabilities will be the only way to install an unsigned operating system.
- XorNot 12y agoBingo: I'm far more afraid of hardware that's actually unhackable. Down that road lies the slow death of start ups, activism, DIY programming etc. I'm actually really happy the tablet revolution didn't pan out as predicted since it leads to the same conclusion: computers where you can't just start coding on them, without which I would never have gotten started.
- pdkl95 12y agoThe War On General Purpose Computing continues. Far too many people are content to sacrifice their future in exchange for a few shiny beads^H^H^H^H^H"smart" devices. As for tablets: they may not have been the revolution that some people hoped for, but the lock-in to a walled garden happened anyway with the iphone. Apple has done more long-term damage to the computer industry than anybody else by convincing way to many software authors - who should really know better - that paying to write and publish software is sane. Instead of fighting this when it was small, we are now faced with a future where even the hardware can work against the user who wants a true General Purpose Computer. We've already seen BIOS lockouts such as the recent thinkpad "boot guard" idiocy. It will get really bad once we start to see Intel "SGX" and the "trusted execution environment" it is intended to enable[1]. So now we get to fight at the hardware level, too. As for using vulnerabilities to root the device - that is not a strategy to fight this, and merely cedes the fight to the people that are afraid of what it means to be "turing complete". Unfortunately, I suspect that we are too late. Fighting this trend now requires sacrifice. Stop giving any money to any business that uses these anti-user technologies. Yes, that includes Intel and many others. Stop writing software or making embedded products that rely on these kinds of features. Yes, this might mean quitting a nice job. No, I expect instead that the people that should know better will continue supporting the enemy by buying their products. I expect they will stay on as collaborators. [1] this should scare anybody that wants a future where that still has general purpose computers: http://www.arm.com/images/GP_Standardization_500.png http://www.arm.com/images/GP_Standardization_500.png
- kuschku 12y agoTPM /could/ be nice, if you personally would control it, instead of some company burning the signing keys into the processor – because then you would be able to make a safe system.
- pgeorgi 12y agoExcept for the Enrollment Key, that's how TPMs work. And the EK is not so much an issue of "control", but of "privacy" - and as long as you control the OS, access to that key (or any other) can be mediated properly.
- indians_pro 12y agoAs someone who is a novice to computer architectures, is there some consensus in the research community about what will be a good replacement for the von neumann machines we are currently running? I mean, if you think about it, if we truly want to take control, shouldn't we attempt to break free, at a ground level, from all the technologies coming from (or dominated by) corporate structures (and government agencies)? x86 (and _64) and even ARM are all primarily developed by govt-influenced companies like Intel, yes? So what are the possibilities of us, all programmers and electronic engineers who want to support personal computing, to get together and develop a crowd-researched, crowd-designed, and (maybe) crowd-funded architecture to last the future. Of course, writing software for that architecture could take decades-centures (unless someone writes a perfect x86 emulation layer on that architecture), but at least that gives us a hope for the future, a backup to fall to if Intel pulls a full on 'google' on us. So are these just big dreams or is there an actual possibility of something like this happening? Especially if the community secures the funding of some visionary who's rich as Bill Gates (maybe the man himself) and on the side of the public? That way we'll be able to actually build a system from the ground up that is libre and transparent, without having to muck about with reverse engineering on the 'enemy's ground', so to speak, like corebook does.
- pgeorgi 12y agoThe problem isn't so much in architectures, but in silicon processes. HomeCMOS (http://homecmos.drawersteak.com/wiki/Main_Page http://homecmos.drawersteak.com/wiki/Main_Page) is notable in being the relatively rare project to look at this layer in the computing stack at all. Once you can do your own processors, the architecture is alright. To avoid running into licensing issues all the time, projects like RISC-V (http://riscv.org/ http://riscv.org/) can help - or open cores like Leon (SPARCv8), OpenSPARC-T1/2 (SPARCv9), openRISC and several more. The problem is, the silicon processes were optimized for investment heavy, large scale operations. To ensure the livelihood of general purpose computing we need a "3D printer for logic gates" (for lack of better term), even if it's economically and technologically less efficient (but not too much, obviously).
- joosters 12y agoThat's a terrible position to take. We don't have to choose between security and freedom (to pick an OS). We can have both. Don't settle for lese!
- RaleyField 12y ago> it isn't a bad thing What isn't a bad thing? Shitty security in BIOS chips? Instead of reformatting your disk you have to detach eeprom chip that holds bios from mobo and connect it to another system to inspect it for infections / changes. I'm not sure this is even possible for most mobos and it doesn't cost nothing like reformatting disk costs nothing. EDIT: > using BIOS vulnerabilities will be the only way to install an unsigned operating system. Then I would rather not use those systems. Android phones are already at this level - I could run CyanogenMod but I'd have to first run a random blob I refuse run because there is no way to verify what that blob does. I'm screwed both ways. At these moments I remember Stallman wasn't completely crazy and wish Linux was licensed under GPLv3 so that the phone I bought wasn't tivoized.
- ghaff 12y ago>At these moments I remember Stallman wasn't completely crazy and wish Linux was licensed under GPLv3 so that the phone I bought wasn't tivoized. In which case Google would most likely simply have used a BSD variant as Apple did.
- indians_pro 12y agoHa. The strange thing about stallman is that his words of 'craziness' magically convert to words of wisdom, but there is always a delay in that process, which can go up to decades. This happens _always_. Joke's on us, despite knowing about this phenomenon, we never adjust for it.
- userbinator 12y agobut I'd have to first run a random blob I refuse run because there is no way to verify what that blob does There's always reverse-engineering... an option which I believe could be far more powerful, and Stallman should've argued for; the ability (and right) to figure out what some software does and modify it is the fundamental key to the freedom he argues for, and while having the source code can certainly help, it's not the only possibility. The power of RE comes from the fact that, while it's very easy to not release source code, it's nearly impossible to prevent someone from reading the binary on a general-purpose computer regardless of what the legal situation is.
- xvilka 12y agoIt sounds very wise, after this: http://arstechnica.com/information-technology/2015/03/windows-10-to-make-the-secure-boot-alt-os-lock-out-a-reality/ http://arstechnica.com/information-technology/2015/03/window...