<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=6752&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / Secure Boot? Yes, we've heard of it ...]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=6752</link>
		<description><![CDATA[The most recent posts in Secure Boot? Yes, we've heard of it ....]]></description>
		<lastBuildDate>Thu, 22 Aug 2024 02:05:03 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: Secure Boot? Yes, we've heard of it ...]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=51790#p51790</link>
			<description><![CDATA[<p>Secure boot is bad, because there is a network stack underneath the operating system running like almost always*</p><p>*unless you disable parts of intel me and coreboot the system.</p><p><img src="https://dev1galaxy.org/img/smilies/wink.png" width="15" height="15" alt="wink" /></p><p>Whose idea was it to put a network stack underneath the OS?</p><p>That only made problems for everyone, linux users included.</p>]]></description>
			<author><![CDATA[dummy@example.com (zapper)]]></author>
			<pubDate>Thu, 22 Aug 2024 02:05:03 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=51790#p51790</guid>
		</item>
		<item>
			<title><![CDATA[Re: Secure Boot? Yes, we've heard of it ...]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=51774#p51774</link>
			<description><![CDATA[<p>while pointed out in another forum thread, the suggested reading is definitely informative and sharable.</p><p><a href="https://dev1galaxy.org/viewtopic.php?pid=51773#p51773" rel="nofollow"> https://dev1galaxy.org/viewtopic.php?pid=51773#p51773</a></p><p>here is a direct link to the suggested reading(in case the original post changes):</p><p><a href="https://easylinuxtipsproject.blogspot.com/p/security.html" rel="nofollow"> https://easylinuxtipsproject.blogspot.com/p/security.html</a></p>]]></description>
			<author><![CDATA[dummy@example.com (stargate-sg1-cheyenne-mtn)]]></author>
			<pubDate>Wed, 21 Aug 2024 10:02:58 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=51774#p51774</guid>
		</item>
		<item>
			<title><![CDATA[Re: Secure Boot? Yes, we've heard of it ...]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=51770#p51770</link>
			<description><![CDATA[<p>some microsoft windows users having problems with a recent update:</p><p><a href="https://arstechnica.com/security/2024/08/a-patch-microsoft-spent-2-years-preparing-is-making-a-mess-for-some-linux-users/" rel="nofollow"> https://arstechnica.com/security/2024/08/a-patch-microsoft-spent-2-years-preparing-is-making-a-mess-for-some-linux-users/</a></p>]]></description>
			<author><![CDATA[dummy@example.com (stargate-sg1-cheyenne-mtn)]]></author>
			<pubDate>Wed, 21 Aug 2024 08:29:55 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=51770#p51770</guid>
		</item>
		<item>
			<title><![CDATA[Re: Secure Boot? Yes, we've heard of it ...]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=51766#p51766</link>
			<description><![CDATA[<p>Slashdot has a story about <a href="https://tech.slashdot.org/story/24/08/21/0031243/something-has-gone-seriously-wrong-dual-boot-systems-warn-after-microsoft-update" rel="nofollow">yet another SNAFU with secure boot</a>. MS attempting to fix a Wind&#039;ohs vulnerability has broken GRUB and people with dual boot systems cannot boot.</p>]]></description>
			<author><![CDATA[dummy@example.com (Micronaut)]]></author>
			<pubDate>Wed, 21 Aug 2024 02:55:52 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=51766#p51766</guid>
		</item>
		<item>
			<title><![CDATA[Re: Secure Boot? Yes, we've heard of it ...]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=51730#p51730</link>
			<description><![CDATA[<p>Http is like the &quot;standard&quot; for everything these days. Everyone and his neighbour&#039;s dog can&#039;t live without http. You can&#039;t do anything with any device without http, even if it&#039;s just to boot locally without a network connection (hint: it won&#039;t work). The day will come when you can&#039;t even go to the washroom without http. Just wait until the hackers hack into a zero day vulnerability in your toilet seat cover.</p><p>It&#039;s absolutely ridiculous, yet nobody&#039;s doing anything about it!</p>]]></description>
			<author><![CDATA[dummy@example.com (quickfur)]]></author>
			<pubDate>Mon, 19 Aug 2024 02:34:16 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=51730#p51730</guid>
		</item>
		<item>
			<title><![CDATA[Re: Secure Boot? Yes, we've heard of it ...]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=51722#p51722</link>
			<description><![CDATA[<p>Why on earth shim has to answer to http requests?<br />I thought that shim is supposed to be just a bootloader.</p><p>O tempora o mores...</p>]]></description>
			<author><![CDATA[dummy@example.com (nahkhiirmees)]]></author>
			<pubDate>Sun, 18 Aug 2024 20:13:24 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=51722#p51722</guid>
		</item>
		<item>
			<title><![CDATA[Re: Secure Boot? Yes, we've heard of it ...]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=51530#p51530</link>
			<description><![CDATA[<p>Good laptops allow uploading your own key. In theory It allows using TPM to decrypt volumes, so that it doesn&#039;t ask for password on boot. But you need to trust laptop&#039;s BIOS (I wouldn&#039;t), and this is susceptible to <a href="https://www.youtube.com/watch?v=RqvPZnLkP70" rel="nofollow">cold boot attacks</a>.</p><p>Apart from being compromised, the default PKE needs to be used with boot loader called “shim”, and it has had <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40547?trk=public_post_comment-text" rel="nofollow">vulnerabilities</a> too.</p>]]></description>
			<author><![CDATA[dummy@example.com (Matlib)]]></author>
			<pubDate>Wed, 07 Aug 2024 23:06:06 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=51530#p51530</guid>
		</item>
		<item>
			<title><![CDATA[Re: Secure Boot? Yes, we've heard of it ...]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=51409#p51409</link>
			<description><![CDATA[<p>@igorzwx<br />ahaha yeah, often it just ends up causing more headaches (much like other Poettering projects, IMO). <br />Personally, I just find it tricky to set up and too buggy in practice. It feels like a temporary fix rather than a real solution.. still waiting for something that actually works smoothly :P</p>]]></description>
			<author><![CDATA[dummy@example.com (lynch9)]]></author>
			<pubDate>Mon, 29 Jul 2024 15:33:17 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=51409#p51409</guid>
		</item>
		<item>
			<title><![CDATA[Re: Secure Boot? Yes, we've heard of it ...]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=51406#p51406</link>
			<description><![CDATA[<div class="quotebox"><cite>quickfur wrote:</cite><blockquote><div><p>a half-assed non-solution to the wrong problem</p></div></blockquote></div><p>Are you talking about pulseaudio?</p>]]></description>
			<author><![CDATA[dummy@example.com (igorzwx)]]></author>
			<pubDate>Mon, 29 Jul 2024 14:36:29 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=51406#p51406</guid>
		</item>
		<item>
			<title><![CDATA[Re: Secure Boot? Yes, we've heard of it ...]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=51404#p51404</link>
			<description><![CDATA[<p>IMNSHO, the fundamental issue with Secure Boot is that it&#039;s solving the wrong problem. As I said before, what&#039;s the point of Secure Boot if the OS it&#039;s going to boot into is insecure? It&#039;s the equivalent of ordering Diet Coke to appease your conscience alongside the 16oz juicy steak you&#039;re eating. </p><p>The first order of business is to fix the lousy OS, then you could meaningfully talk about booting securely. </p><p>Before then, the only thing that you could possibly achieve is merely a half-assed non-solution to the wrong problem. Which about summarizes the past 3 decades of Windows history.</p>]]></description>
			<author><![CDATA[dummy@example.com (quickfur)]]></author>
			<pubDate>Mon, 29 Jul 2024 13:33:32 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=51404#p51404</guid>
		</item>
		<item>
			<title><![CDATA[Secure Boot? Yes, we've heard of it ...]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=51401#p51401</link>
			<description><![CDATA[<p>Hello:</p><p>Great way to start the week:</p><p>From this morning&#039;s The Register ...</p><div class="quotebox"><cite>Brandon Vigliarolo @The Register wrote:</cite><blockquote><div><p>Secure Boot useless on hundreds of PCs from major vendors after key leak<br />Plus: More stalkerware exposure; a $16M TracFone fine; Ransomware victims don&#039;t use MFA, and more</p></div></blockquote></div><p>Snippets from the <a href="https://www.theregister.com/2024/07/29/infosec_roundup/" rel="nofollow">article</a>:</p><div class="quotebox"><blockquote><div><p>... research published last week by security boffins at firmware security vendor Binarily.<br />... found hundreds of PCs sold by Dell, Acer, Fujitsu, Gigabyte, HP, Lenovo and Supermicro – and components sold by Intel – using what appears to be a 12-year old test platform key (PK) leaked in 2022 ...</p></div></blockquote></div><div class="quotebox"><blockquote><div><p>&quot;An attacker with access to the private part of the PK can easily bypass Secure Boot by manipulating the Key Exchange Key database, the Signature Database, and the Forbidden Signature Database,&quot; Binarily&#039;s boffins wrote.</p></div></blockquote></div><div class="quotebox"><blockquote><div><p>... not like the manufacturers using the offending PK didn&#039;t have reason to know it was untrusted ...<br />It said so right on the package.</p></div></blockquote></div><p><a href="https://www.youtube.com/watch?v=_SVSak1oBCw&amp;list=PLYSJjOQbyvz-2gHMxGxByh0fnc2vZMFij&amp;index=2" rel="nofollow">Very interesting</a> how secure the boot ended up being.</p><p>Best,</p><p>A.</p><p><span class="bbu">Edit</span>:<br />Just noticed another previous <a href="https://dev1galaxy.org/viewtopic.php?id=6749" rel="nofollow">post</a> here about this problem.<br />No matter: 50+ years later, Arte Johnson can <em>still</em> make me laugh out loud with his routines.<br />Much needed these days.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Mon, 29 Jul 2024 09:56:15 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=51401#p51401</guid>
		</item>
	</channel>
</rss>
