Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Foxboron
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
61.
▲
by
Foxboron
2y ago
> This is a weird point, and concerning if it is true, because it seems to assume Arch's rolling release model is a bad model that the Arch team are forced into due to lack of funds, whereas for most of us it is in fact one of the m
62.
▲
by
Foxboron
2y ago
Partially. David Runge held a talk about the Secure Signing enclave at All-Systems-Go. https://media.ccc.de/v/all-systems-go-2024-263-boring-infras...
63.
▲
by
Foxboron
2y ago
There is a reason why Hylang was one of the first official Docker images!
64.
▲
by
Foxboron
2y ago
and for those interested in history, Docker was first announced 10 minutes afterwards on the 26:24 mark.
65.
▲
by
Foxboron
2y ago
Super happy Hy 1.0 has been released! It was the first proper open-source project I contributed towards and I don't think I would have been as engaged as I am in the community without it.
66.
▲
by
Foxboron
2y ago
Nobody forced us, Arch Linux, to adopt systemd.
67.
▲
SSH CA with device and identity attestation: SSH-tpm-ca-authority
(linderud.dev)
2 points
by
Foxboron
2y ago
|
0 comments
68.
▲
by
Foxboron
2y ago
https://en.wikipedia.org/wiki/Debian%E2%80%93Mozilla_tradema...
69.
▲
by
Foxboron
2y ago
It's not 2006 anymore.
70.
▲
by
Foxboron
2y ago
At which point us, the Linux packagers and other package maintainers, is just going to patch it out. I wouldn't be very worried.
71.
▲
by
Foxboron
2y ago
You could also include SSH keys as public secrets. https://github.com/Foxboron/ssh-tpm-agent
72.
▲
Sbctl 0.15 – Secure Boot key manager
(github.com)
2 points
by
Foxboron
2y ago
|
0 comments
73.
▲
by
Foxboron
2y ago
> Not to mention that much of Nix packages are reliably bit-for-bit reproducible. We don't know that. Nobody has even attempted to build more then an incredibly small fraction of the packages `nixpkgs` provides.
74.
▲
by
Foxboron
2y ago
> Is that not correct? It's not. That would be comparable to magic.
75.
▲
by
Foxboron
2y ago
> Hi Fox, i'm not aware of any other usages on the platform i'm familiar with sorry, maybe a gap in my understanding. The TPM as a device is completely democratized and accessible by the normal user. You can use it for platform
76.
▲
by
Foxboron
2y ago
If ARM implements the UEFI specification then there are escape hatches to enroll your own PKI. I don't own ARM machines with UEFI so I have no clue.
77.
▲
by
Foxboron
2y ago
> Hyperbolic or fairly extreme-sounding scenarios are common when discussing this kind of thing, partly because it makes discussion about a fairly boring topic a little bit more interesting. Don’t get distracted by that. It's not. T
78.
▲
by
Foxboron
2y ago
> Also most (all?) UEFI systems are not locked to Windows and allow customizing the keystore via the firmware console interface anyhow. All of them. The Secured Core machines still allows you to reset Secure Boot into user mode as mandat
79.
▲
by
Foxboron
2y ago
> You're not binding the secret to PCR values? I thought TPM fans loved those things? Binding things to PCR values doesn't imply you need Secure Boot, signed initrd, lockdown mode, shim and signed kernel modules. All of these t
80.
▲
by
Foxboron
2y ago
> I'll admit that's a benefit, but it seems very small benefit considering the far-reaching changes it's needed like kernel lockdown mode, the microsoft-signed shim, distro-signed initrd, the difficulties it creates with D
81.
▲
by
Foxboron
2y ago
> Do i need to? That the user presses the power button does not mean the machine will freshly boot. It could also be an unsuspend/wakeup or some regular ACPI event if the machine is only appearing to be off. This is a completely ima
82.
▲
by
Foxboron
2y ago
> The OS does not matter? Of course it does. You are replaying the logos and screens. > Grab the video output via HDMI/DisplayPort and insert the keypresses via USB. Thats likely gonna work. Basically what modern KVM switches do.
83.
▲
by
Foxboron
2y ago
It's not meant for Secure Boot. They are two separate, but adjacent, technologies that provide their own security properties in a boot chain. This is a common misconception.
84.
▲
by
Foxboron
2y ago
> But the whole point of binding a key to hardware is to be secure even if a remote attacker has gotten root on your machine. An attacker with root can simply replace the software that reads your PIN with a modified version that also sav
85.
▲
by
Foxboron
2y ago
> The same way the fake laptop can relay your password to me, i could also relay the generated TOTP code from the stolen laptop to the fake in front of you. Also any authentication to generate that TOTP in the first place. As tried to co
86.
▲
by
Foxboron
2y ago
It's never unsealed. `tpm2-totp` does an encrypted session to the TPM and runs `TPM2_HMAC` on the TPM shielded key, you can also include PCRs to add further authentication to this entire exchange. What do you mean with "relay"
87.
▲
by
Foxboron
2y ago
You need to decide between the attack here. Are you subverting hardware or are you replacing a laptop? The TOTP token here is sealed inside TPM.
88.
▲
by
Foxboron
2y ago
> For us, the benefits of TPMs and measured boot for personal use are a lot more obscure. You'll sometimes hear people claim it protects against 'evil maid attacks' where an attacker repeatedly gets physical access to your
89.
▲
by
Foxboron
2y ago
`tpm2-totp` defeats the entire "replace the laptop" threat scenario. https://github.com/tpm2-software/tpm2-totp
90.
▲
by
Foxboron
2y ago
Glitter nailpolish on your machine seams/screws and tamper detection. Keyboard sniffing is not as trivial as people make it out to be.
More ›