Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mkopec
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
TrenchBoot DRTM Launch of Xen on Intel Sapphire Rapids
(youtube.com)
3 points
by
mkopec
10d ago
|
1 comments
2.
▲
by
mkopec
10d ago
Platform: ASRock Rack SPC741D8, Xeon Sapphire Rapids. Firmware: Dasharo, coreboot + edk2 payload. Launch path: GETSEC[SENTER] with the SINIT ACM, Xen and dom0 measured into PCRs 17-18.
3.
▲
Automating Firmware Security: CI for DBX and Microcode Updates in Dasharo
(blog.3mdeb.com)
4 points
by
mkopec
1y ago
|
0 comments
4.
▲
by
mkopec
2y ago
> If all DVD players came with watermark detection instead of copy protection That is an enormous "if". Do you think Microsoft is going to or is able to enforce this on every single software provider? Even in your Android examp
5.
▲
by
mkopec
2y ago
Google SafetyNet is basically swiss cheese with lots of bypass solutions for custom ROMs. A TPM may only attest that it has received an expected set of measurements (hashes). As long as discrete TPMs or PCs with unlocked CPUs exist (w/
6.
▲
by
mkopec
2y ago
Widevine L1 requires a trusted execution environment for decrypting video and only showing it on HDCP monitors. It's built on top of Intel PAVP, AMD secure display, or ARM TrustZone in the case of ARM chromebooks and Android devices. T
7.
▲
by
mkopec
2y ago
> Does TPM support/requirements actually have any meaningful impact on a home user? Disk encryption, Windows Hello and PIN bruteforce prevention. I have no love Microsoft and avoid using Windows whenever I can, but I think making th
8.
▲
by
mkopec
2y ago
There are none. It's so immensely frustrating to me that so many people believe that a TPM is a DRM device. I'm sure Richard Stallman's Treacherous Computing article played a big part in this. A TPM is useless for DRM, and th
9.
▲
Research of RAM data remanence times
(blog.3mdeb.com)
35 points
by
mkopec
2y ago
|
6 comments
10.
▲
by
mkopec
2y ago
I think if the process was made easy, it would save quite a bit more than 1% of these devices from the landfill, assuming you have enough power users to build a community. Plenty of people flash their chromebooks to MrChromebox UEFI to give
11.
▲
by
mkopec
2y ago
I firmly believe that permanent key fusing to lock bootloaders should be outlawed. At the very least the keys (and schematics) should be released once the device reaches EOL. Otherwise we're just manufacturing e-waste.
12.
▲
by
mkopec
2y ago
Yeah, that's not something anyone should be saying to random people online.
13.
▲
by
mkopec
2y ago
Do Android Auto and VoLTE / VoWiFi work on Graphene these days? I also remember Google Maps and Uber being extremely problematic
14.
▲
by
mkopec
2y ago
Application Processor, i.e. the main processor
15.
▲
by
mkopec
3y ago
I would like to be able to ensure that only boot loaders signed with my private key can be executed. Secure Boot serves that purpose well, can I do that with your approach? Likewise, demand and use cases for network boot exist, otherwise it
16.
▲
by
mkopec
3y ago
Rust won't magically fix every vulnerability and someone would have to pay a team of engineers to rewrite everything.
17.
▲
by
mkopec
3y ago
Some piece of code has to configure the CPU, initialize memory before you can even think about loading an OS...
18.
▲
by
mkopec
3y ago
All Zen 1 CPUs and newer have the PSP / ASP security processor which is ARM based and runs before the x86 cores are released from reset. This applies to all Zen models, not just the PRO versions. The fTPM does indeed run on the PSP, so
19.
▲
by
mkopec
3y ago
I think ChromeOS Freon was close to what you're describing, but they ended up switching to Wayland at some point
20.
▲
Trustworthy Platform Module
(twpm.dasharo.com)
3 points
by
mkopec
3y ago
|
0 comments
21.
▲
by
mkopec
3y ago
Dropping a link to a project attempting to create a fully open source TPM: https://twpm.dasharo.com/
22.
▲
by
mkopec
3y ago
In what manner specifically does a TPM not belong to the user, while a YubiKey does?
23.
▲
by
mkopec
3y ago
Right, but then the crawler devs will google this weird 999 code and handle it as a 429. If I wanted to mess with clients I don't like, I'd just return a random valid code.
24.
▲
by
mkopec
3y ago
Disappointed with Lenovo's decision to enable PSB on my T14, having previously hoped one day I'd run coreboot on it, I decided to write a checker and crowdsource a list of PSB-enabled devices so that others may avoid buying hardwa
25.
▲
Show HN: A little script to check if your Ryzen PC uses Platform Secure Boot
(github.com)
3 points
by
mkopec
3y ago
|
1 comments
26.
▲
by
mkopec
3y ago
Indeed, it seems that having another unlock option might be preferable. If you value your own live over the secrets, that is.
27.
▲
by
mkopec
3y ago
It's a matter of priorities, I guess? If you want to you can just not save the recovery password. In that case I guess they'll just beat you to death with that $5 wrench.
28.
▲
by
mkopec
3y ago
With LUKS you can enroll an extra auth option in addition to TPM, like a password or a FIDO2 token.
29.
▲
Dasharo Compatible with MSI Pro Z690-A Release v1.1.2
(blog.3mdeb.com)
2 points
by
mkopec
3y ago
|
0 comments
30.
▲
by
mkopec
3y ago
Well you can't hack the firmware :( A baffling decision considering the brilliant work they're doing otherwise. I do not see a reason why they absolutely need to have Intel Boot Guard enabled. I'm at the point where I'm
More ›