Damus

Recent Notes

Mr Penguin · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqq45hz09g0dvshschpjss656arfefcrgn99p7x9q07dwakn34wense8chn9 That's a lot of requirements. First, no one said it could be attacked without a connec...
sister_sam profile picture
@nprofile1q... Core boot source is out there, no? openWRT is open source. So that criteria seems satisfied.
When we cannot see the code we can't say if security issue are or are not present except by the evidence from outside the code. I didn't act like anything. I asked questions in case I missed something I can actually do anything much about.
1
Mr Penguin · 3d
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqq45hz09g0dvshschpjss656arfefcrgn99p7x9q07dwakn34wense8chn9 When you flash coreboot you aren't replacing the entire 'bios' or all the code that makes it up factoring in the various components. Libreboot is a fork or was a fork prior that ripped...
Mr Penguin · 2w
"Vermont Attorney General Charity Clark applauded the decision, saying it affirms 'that companies that choose to do business in Vermont, like Meta, can be held accountable when they harm kids.'" THEY...
sister_sam profile picture
@nprofile1q... Proving the harm is the sticky part. Allegations shouldn't lead to any action but exploring the truth of it. Social media harms kids is the latest variant of video games harm kids is the latest variant of rock and roll harms kids. And all of it wants to "fix it" by giving the State more power.
Funny how that works.
Mr Penguin · 4d
"Arch Linux Malware Incident: Malicious Commits Found in 1,579 Packages" Ymm yea... see I knew there was a reason I have never been a fan of Arch. I may be a laissez-faire proponent when it comes t...
sister_sam profile picture
@nprofile1q... Doesn't have much of anything to do with arch as the packages are not linux variant specific and there is limited time and expertise to catch all issues.
In Debian it can take a lot longer for a fix to propagate. Of course that is a two-edged sword.
1
Mr Penguin · 3d
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqq45hz09g0dvshschpjss656arfefcrgn99p7x9q07dwakn34wense8chn9 I'm not sure what you were trying to say, but I think it was more along the line of the AUR repository is not Arch, but a repository for Arch of user maintained packages. If so that's c...
Mr Penguin · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqq45hz09g0dvshschpjss656arfefcrgn99p7x9q07dwakn34wense8chn9 Coreboot doesn't stop ME. ME is essential to bringing up and initializing all modern I...
sister_sam profile picture
@nprofile1q... But what can be done with the remaining part of ME against me and in what context precisely? Show me how having an x86 coreboot router running openWRT can be successfully breached without physical presence for instance. Otherwise it is noise.
1
Mr Penguin · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqq45hz09g0dvshschpjss656arfefcrgn99p7x9q07dwakn34wense8chn9 That's a lot of requirements. First, no one said it could be attacked without a connection to the outside world which is pretty much a safe assumption if it's a routing device of any kin...
Mr Penguin · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqq45hz09g0dvshschpjss656arfefcrgn99p7x9q07dwakn34wense8chn9 I can't get into too much detail regarding the bit. I'm more inclined to work on real ...
sister_sam profile picture
@nprofile1q... x86 is something I know very well. I don't see how mere opcode set is the problem. Coreboot is supposed to stop ME. How does it not.?

I am more interested in more private and secure systems and software. We don't have to go backwards in capability to do that. All for the good fight in depth as long as the perfect doesn't become enemy of the actually pretty good or at least much better.

2 GB of ram is worthless for most everything today So not an option.

32 GB is good. I don't buy machines except ultra portable laptops with less than 32 GB. And for small laptops nothing less than 16 GB. My physical machines are kept too busy for less.
2
Mr Penguin · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqq45hz09g0dvshschpjss656arfefcrgn99p7x9q07dwakn34wense8chn9 Coreboot doesn't stop ME. ME is essential to bringing up and initializing all modern Intel based systems. What happens when you "disable" it is that the system boots, half the ME is or ...
Mr Penguin · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqq45hz09g0dvshschpjss656arfefcrgn99p7x9q07dwakn34wense8chn9 I understand the sentiment, but I think this is not quite the right way of looking at it. There are some things you need to be ultra secure. Think communications between two locations. Y...
Mr Penguin · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqq45hz09g0dvshschpjss656arfefcrgn99p7x9q07dwakn34wense8chn9 Are you familiar with TR-069? It's the protocol that gives ISPs backdoor access to you...
sister_sam profile picture
@nprofile1q... Just read up. Very bad news and part of CALEA in US IFF you are using ISP provided modem and router (or combined as many are) . However I am safe from it ath ONT is terminated at a router I control that does not have any support for TR-069 whatsoever.

Really good for people to be aware of how government can crawl up our ass with such as this.
Mr Penguin · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqq45hz09g0dvshschpjss656arfefcrgn99p7x9q07dwakn34wense8chn9 I wouldn't dispute that the backdoor in the ME is a bit overplayed. However, it's me...
sister_sam profile picture
@nprofile1q... Yeah. First think I did with Fidium provided router is look for such stuff. They shipped it with uPnP on "as a convenience". Turned it off of course along with their other helpful "protection" that made connecting Cake Wallet over WiFI fail. And the rest of it will be replaced as soon as I finish setting up the ProtectLi.
1
Mr Penguin · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqq45hz09g0dvshschpjss656arfefcrgn99p7x9q07dwakn34wense8chn9 Are you familiar with TR-069? It's the protocol that gives ISPs backdoor access to your routing/modem hardware. The government(s) apparently using it, though how often I do not know, and...
Mr Penguin · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqq45hz09g0dvshschpjss656arfefcrgn99p7x9q07dwakn34wense8chn9 Yes, coreboot doesn't solve all the security concerns, but it does enable you to partially disable the ME, and likely the security issue with the 'backdoor'.
Mr Penguin · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqq45hz09g0dvshschpjss656arfefcrgn99p7x9q07dwakn34wense8chn9 I can't get into too much detail regarding the bit. I'm more inclined to work on real solutions to these problems than I am to pander to those working on projects that don't really solve...
Mr Penguin · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqq45hz09g0dvshschpjss656arfefcrgn99p7x9q07dwakn34wense8chn9 There is a BIOS and other small bits of code here and there at a lower level. From har...
sister_sam profile picture
@nprofile1q... It has been 50 years since I wrote or cared to write all the bits of an entire machine. I work today at deepest level I am willing to go to. It is enough for me. In my youth I wrote everything starting with raw hek. Now I have other things to do. And I certainly don't think that unless we go all the way to machine code that it is pointless to bother at all. That would be horrific learned helplessness.

I do not agree there is that strong evidence of BIOS backdoors to worry about. I eliminating the ISP shipped components except for the modem itself.

I think the remote management scare is a bit overplayed as it is not workable without hardware access on most machines as shipped in my understanding. .
1
Mr Penguin · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqq45hz09g0dvshschpjss656arfefcrgn99p7x9q07dwakn34wense8chn9 I wouldn't dispute that the backdoor in the ME is a bit overplayed. However, it's merely an example of why we should be concerned whether or not it's being actively used. It's probably...