Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Foxboron
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
22 ms
·
211.
▲
Show HN: Release 0.8 of sbctl, Secure Boot key manager
(github.com)
7 points
by
Foxboron
5y ago
|
0 comments
212.
▲
by
Foxboron
5y ago
I wrote "Reproducible Builds has standardized". I made no assertions how this is recognized in the wider ecosystem. However, a couple hundred projects heed this standard along with most distributions. Does your nitpicking really m
213.
▲
by
Foxboron
5y ago
Man, if people just took the time to read the link and not the comment :)
214.
▲
by
Foxboron
5y ago
Please read the link. Reproducible Builds has standardized "SOURCE_DATE_EPOCH" for exactly this usecase. Introducing other variable names i just going to cause more problems. https://reproducible-builds.org/docs&#x
215.
▲
by
Foxboron
5y ago
Such rebuilds systems are complicated and might not work 100% when you first start out. There can be multiple complete rebuilds done while removing edge-case bugs that either fails the building or introduces variance into the builds.
216.
▲
by
Foxboron
5y ago
>Why are 28.8% of Debian stable packages currently "pending"? They are separate systems. The CI/CD and the rebuilder are not doing the same job essentially. The 28.8% on pending might be because of slow rebuild times as th
217.
▲
by
Foxboron
5y ago
Sadly, they are not "real" numbers. This is taken from the integration suite which Debian have been running for years. This represents checking out the code, and building twice. This is not distributed packages from Debian. This i
218.
▲
by
Foxboron
5y ago
This blogpost can be summarized as with an XKCD essentially. It positions itself with the following assertions: > Q. If a user has chosen to trust a platform where all binaries must be codesigned by the vendor, but doesn’t trust the vend
219.
▲
Reproducible builds for Debian: a big step forward
(qubes-os.org)
125 points
by
Foxboron
5y ago
|
55 comments
220.
▲
by
Foxboron
5y ago
It's intentional and normal. Academic papers traditionally write in plural form (regardless of co-authors) as it feels more inclusive towards the reader.
221.
▲
by
Foxboron
5y ago
It is less secure. The initramfs is not signed, along with the microcode.
222.
▲
by
Foxboron
5y ago
>Is that somehow configurable from Linux distribution's setup, or it will require user to manually set a BIOS password? (and it requires the user to set a different bios password. if the user sets the same password for fde and for b
223.
▲
by
Foxboron
5y ago
>But okay, you may extend my attack by saying that you exchange the motherboard between the victim and the attacker laptop, so that you don't need to replicate the chassis. Modern computers has tamper detection and if you open them
224.
▲
by
Foxboron
5y ago
sysfs doesn't like some optionroms, so using the rom files from there wont work in some cases. Apparently they can be stored in an ACPI table.. but I haven't looked at it. Another alternative is to read the TPM2 eventlog. It shoul
225.
▲
by
Foxboron
5y ago
Keeping it on a seperate blockdevice allows dm-verity to authentice the device. This value would be signed and secured, so injecting a signed+known library wouldn't work. It would refuse to mount. It should be noted that keeping it une
226.
▲
by
Foxboron
5y ago
In theory. But part of the UEFI boot chain is Optional ROM files stored on hardware. Most commonly found on dedicated graphics cards and other hardware. All of these files need to be authenticated, and currently signed by Microsoft or the O
227.
▲
by
Foxboron
5y ago
I don't think a 5 year old project linked without context is appropriate when talking about modern boot chain security. It doesn't even support stubs so it fails at the first threat scenario described in this post.
228.
▲
by
Foxboron
5y ago
No, the last update was that the plan is to keep mkinitcpio and other alternatives maintained. https://lists.archlinux.org/pipermail/arch-dev-public/2021-F... This is also why I started writing up the feature.
229.
▲
Mkinitcpio v31 and UEFI Stubs
(linderud.dev)
42 points
by
Foxboron
5y ago
|
12 comments
230.
▲
by
Foxboron
5y ago
Very similar to qutebrowser. But instead of being electron it's on qt-webengine. https://qutebrowser.org/
231.
▲
by
Foxboron
5y ago
I'm still not sold on the idea of having something bound by OIDC identities with Google/RedHat as stakeholders. Looking at the general conversation about FOSS developer identity that has been happening on OpenSSF, what are the act
232.
▲
by
Foxboron
5y ago
patchelf is not really widely used for solving reproducible builds issues. It's made for rewriting RPATHs which is essential for NixOS, but not something you would be seeing in other distributions except for when someone need to work a
233.
▲
by
Foxboron
5y ago
I feel the need to point out that the "Bootstrappable Builds" project is a working group from a Reproducible Builds project which where interested in the next step beyond reproducing binaries. Obviously this project has seen most
234.
▲
by
Foxboron
5y ago
Indeed, and with the work done by Guix and the Reproducible Builds project we do have a real-world example of diverse double compilation which is not just a toy example utilizing the GNU Mes C compiler. https://dwheeler.com/
235.
▲
by
Foxboron
5y ago
And Arch Linux :) https://reproducible.archlinux.org/
236.
▲
by
Foxboron
5y ago
>- Nix tooling was created 15 years ago exactly for this, Nix is mad to make packages bit-to-bit rebuildable from scratch. I don't think this is accurate? Nix is about reproducing system behaviour, largely by capturing the depende
237.
▲
by
Foxboron
5y ago
Seems like 2 Arch Linux maintainers have now been klined after they (again) took over ##archlinux to redirect people back to #archlinux.
238.
▲
Goodbye Freenode
(nedbatchelder.com)
279 points
by
Foxboron
5y ago
|
118 comments
239.
▲
by
Foxboron
5y ago
I have been trying to improve the usability of secure boot key management on Linux for the past year by writing some libraries from scratch and sbctl. I have even started writing full integration testing with tianocore/ovmf! https:&#x
240.
▲
by
Foxboron
5y ago
We are missing unprivileged builds and clean chroot builds for `makepkg`. Our interal devtools uses `systemd-nspawn` which requires root. But that should be easy to implement with the leftover code we tried to use with our reproducible buil
More ›