HN user

devops99

12 karma
Posts0
Comments145
View on HN
No posts found.

Did Spafford threaten the neighbors directly?

In a legal context, and also the real world sans a legal context, words do have meaning and words do matter. I don't see anything in the article that Spafford terrorized anyone.

Whether Spafford intended to terrorize anyone in the future is another matter, and a matter of legitimate and serious concern. But we must not confuse this with "terrorized" (past tense) if we are going to discuss the matter in a sane and sober way.

Thank you for prompting attention to the switcheroo.

This angle of attack is generally unheard of, but should be considered. I can think of some mitigations that can work.

Tamper-evident materials are well-known by the crowds that will target users. There are many criminals among us, so many that those who don't have criminal psychology have a hard time wrapping their mind around it. Given this, I am cynical, and every defense within reasonable cost should be leveraged.

The more inexpensive option of the newer Trezor wallets and "login PIN" as an optional alternative to a password that also works, seems to be the best option (that I have seen so far).

The more recently released Trezor wallets are still new, and Yubikey 5C will probably be used in many places anyway just because of the keyring and no need for the usb-c cable.

vs. FDE with a boot key stored in some cloud service secured with the user's password instead of a TPM

Without secure boot (backed by TPM), I can boot a small USB device that has LEDs on it to indicate to me that the target system has been infected to send me a copy of the target's password, after I already imaged the disk (or when I have another team member steal it or take it by force later).

If there's a UEFI password to access UEFI settings, I can reset it in under 20 minutes with physical access. Some tamper-evident tape on the laptop casing may stop me if I haven't already had a resource intrude into the target's home/office to have some replacement tamper-evident sticker material ready. Very very few places, even some really smart ones, make use tamper-evident material. Glitter+glue tamper-evident seals are something I can't spoof though.

It's not that hard to get into a hotel room. Often enough if a business books a hotel for you it's because they want access to your laptop while you're at lunch with another employee who so kindly suggests to leave your backpack in the hotel room.

disclaimer: all above is fictional and for educational and entertainment purposes only

I agree. TPM defends against the most likely threat that typical users are facing. And, where users that are individually targeted, the theft/robbery will more often than not be designed to appear "random".

Because TPM sniffers are now at a material cost of about $15 and can be acquired for a price at under $200, more than a TPM is needed for data encryption, especially for users like a CEO. This is why a firm I used to work for encrypted the key that could unlock user data with both TPM plus Yubikey.

there is no standardisation in connectors, pinout, or bus type when it's not soldered onto the board. I have three motherboards with plug-in TPMs and each required a different, unique part that was difficult to source.

This should be prohibited by commercial law.

We have had "FDE" and secure boot with TPM in higher-than-commercial (defense) and the higher end of commercial settings for Linux, BSD, and illumos since TPM 1.2 was available, and I'd have to dig in some places to confirm but probably before Windows did in actual practice anywhere (let alone officially).

Yeah, Debian/Ubuntu, Fedora, etc didn't have this, but as the saying goes: you get what you pay for. Although enough of the Gentoo users (the real Gentoo users) have such a thing had it around that time too, if they wanted it (and they tend to put together what they want).

Some essential context: if you think the "Linux community" is elitist, wait until you see the niche commercial (and higher) players. I'm probably an example of such, to be fair.

Common use cases, are, "as a Developer / DevOps practitioner, I want for":

  - a client (company I do contract work for) sees a different source address that is different than the source address I use for casual browsing+posting.

  - two SaaS used for purposes of servicing agreement with "client" don't see the same source IP address as used for other clients.

  - a bank I use, and PayPal, always sees the same source IP address dedicated to my VPN account only and for this purpose.

  - the tunnel (VPN) provider I use for casual browsing+posting does not see the destination IP address of my client's VPN.

  - whatever first-hop ISP I use sees one single Wireguard tunnel and nothing else ever.

  - the first-hop Wireguard tunnel is paid for with a pre-paid debit card, but any outbound TOR traffic is encapsulated by a secondary tunnel paid for with crypto.

  - the TOR circuit used for browsing purpose A is not also shared by browsing purpose B.

  - any arbitrary outbound tunnel is specific to the container or VM I intended to use but doesn't carry, nor has any risk of carrying, any of my other traffic.

Tor is important to me because I have a right to read.

There is no crime within Common Law for any of the above. Nor is there any violation of any statute for which any of the above is, per doctrine of minimum contact (such as with a pre-paid debit card), within jurisdiction of statute.

Perhaps some users do operate with some concern of being "busted", but most users that do outbound network path management do not operate with this concern.

of people who actually appreciate the threat model enough to keep spending extra effort

The "product" is already successful. Some spent effort, others spent money.

Those who did the latter include defense contractor or other government backgrounds, ""conservative"" (aka normal people) moms who were censored on Facebook and Twitter as early as 2019 and had enough pattern recognition to know the unlawful censorship reached all the way up into the federal government, journalists, and some are in the category of politician.

Think of what Tucker Carlson shared with the public "the NSA got into my Signal account, which I didn't know they could do". I don't expect our solution to stand up to NSA, but unlike a retail device the starting point of the digital playing field on my camp's solution doesn't let digital intrusion be a cakewalk for "glowies" like retail devices do. Glowies have to work significantly harder to compromise what we have.

Some of the "Instagram famous" gen Z stereotypical "hot girls" who are computer illiterate and generally aloof (vapid on the surface) were immediately willing to tolerate the overhead of "touchscreen cabled to a backpack" when they were told "when you do a call with mom or dad, that call does actually stay protected". Trashy aka "low socioeconomic status" people don't give a shit about family privacy/autonomy, but these people do give a shit about it.

All aforementioned categories of users have already experienced suffering abuse, or anticipate being abused, or they simply have enough dignity in their life that they're not going to just give it away like typical retards do ; they are not going to "eventually move on" from "this computer I carry on my person every day is not designed for me to get fucked over" and then downgrade to a retail device that is by design (in one way or another) positioned to fuck them over. Sans a "burner" device for some specific narrow purpose (Instagram presence) that has had its internal mic gutted and has hardware shutters on its cameras.

The technical concept is what I am allowed to post about so that's what I did. As I already wrote earlier (and also then later cited I had written), something cohesive will be posted later this year, and if the person I expect to do it doesn't then I'll do it myself. Or, one of the other existing players in the space will, or someone else entirely (and I'd be perfectly happy with that).

.

You're not sitting on some super special idea here

I appreciate you acknowledging this point, a point that I had emphasized, and I feel I had done so rather clearly, several times above. Many Qubes users have been doing this since 2018.

The essential thing my camp did that was "special" was package it professionally in a way that "normie" users can succeed with it out-of-the-box.

Like with any specific operating system and hardware combination there are implementation specific bugs here and there, but nothing major.

.

how far I could get without a proper voice plan.

Some use "2FA mule", like this https://kozubik.com/items/2famule/ ; though we advise to physically remove the microphone of the 2FA mule and presume any WiFi/Bluetooth traffic from it is hostile.

Those who need PSTN (legacy phone network) voice or 911 can use another device for that.

No one using our mini-backpack is missing out on any functionality they actually need.

.

eg what specific dev boards straightforwardly run Graphene? I don't see any listed on the website

I do appreciate you bothering to look. I actually do. There are boards that can run with zero blobs, they are intended for production use as sold, so long as they can run a Linux kernel and have a GPU that Android can use, they can run GrapheneOS.

Our solution is not supported nor known about by the GrapheneOS project, we have our own branch and cicd and all that.

.

Which is probably how I ended up skipping over some actual details.

Yeah, the performance (or lack thereof) of your reading comprehension has been rather noticeable.

.

the polar opposite of the trash elitist attitude you're pushing.

Okay but no matter what happens, I will always get more money and more pussy than you.

In response to the comment further above (so not just the article), outbound network path management is not uncommon. However we often see it presumed to be uncommon by those who haven't thought of it, or have thought of it but the ability to do it is out of their reach.

Qubes makes outbound network path management easy enough but it's not too hard to do on Linux and FreeBSD, so it can also be done on machines with modest compute resources (which may or may not be subject to the machine being an older machine) as well.

There are times in human history where there was more intense "space weather" in the solar system. These events were much more spectacular -- is in a much greater spectacle -- than the most spectacular events we know today which are eclipses.

In more ancient history there was obsessive worship of the planets on every habitable continent. Today we have a more scientific explanation for what was happening then, even if we don't see the same spectacles today.

  https://en.wikipedia.org/wiki/Birkeland_current

Flipping the HAP bit on the Intel ME/AMT on older laptops is less difficult, generally (not always). However, with more recent UEFI releases containing newer Intel ME/AMT payloads, the HAP bit is benign on these newer releases of Intel ME for all we know.

There is a very dire need to have those with hardware hacking skills assist the larger freedom software community in "liberating" newer machines.

Someone recently got Libreboot running on a ThinkPad T480

  https://ezntek.com/posts/librebooting-the-thinkpad-t480-20241207t0933/

Basically this.

And, hopefully your USB stack, or your phone's equivalent to SIM interface, doesn't have vulnerabilities that the small computer that is the SIM card could exploit.

Operating systems that center their efforts on protecting high risk users like Qubes dedicated a whole copy of Linux running in a Xen VM to interface with USB devices.

It'd be great if more information were available on how devices like Google's Pixel devices harden the interface for SIM cards.

How about you tell the former CEO of Qwest, or William Binney, or Jacob Applebaum how it is you are so sure you think the world works. I implore you, respectfully, to consider what they have told the world and give some time, on top of the time you have probably already given this topic -- give some extra time to this topic, after seeing what they have shared with us.

  https://www.vice.com/en/article/the-telecom-exec-who-refused-nsa-snooping-is-out-of-prison-and-hes-talking/

  https://en.wikipedia.org/wiki/William_Binney_(intelligence_official)#Whistleblowing

  https://media.ccc.de/v/30C3_-_5713_-_en_-_saal_2_-_201312301130_-_to_protect_and_infect_part_2_-_jacob

> and businesses generally push back very strongly against governments whenever a government asks them to do things that will cause them to make less money and/or waste money.

Did Facebook and Twitter do this when the federal government told them to censor?

What did Mike Benz' interview with Tucker (whether you dislike or like Tucker is neither here nor there so let's not get distracted by that) in February of this year (2024) reveal to all of us?

of big tech to have any desire to do this kind of thing.

Apple is and always will be subservient to NSA, CIA, and the State Department. If you believe today -- after taking a moment to really, truly, seriously think about it -- that it is the other way around, you have a very special kind of stunted personal development.

(including security engineering teams) within the company...

I respectfully implore you to look into the publicly available information about how many people at Facebook, Google, Twitter (pre-Musk), and Apple have NSA or other "glowie" backgrounds.

well that seems like a recipe for getting some of the company's most talented and highly paid security engineers incredibly pissed off

You are correct here.

if they ever find out

They won't, not unless they already have the appropriate clearance, and once they do they will take those secrets to the grave, or else -- unless they can make it to Moscow instead of a black site operated on foreign soil.

and it's very likely they would eventually find out

Provided they can get into parts of buildings, buildings that aren't even on the same campus, that they aren't authorized to get into, which will never happen. So..

I would at a later time directly link to you the next-generation builds that we do have permission (the previous was not my corp) to make public-facing in 2025, as I already wrote in another comment. However, your overall reply is kind of dumb. So, if you feel you are entitled to demand a "finished product", build it yourself.

And, yes, I will continue to look down my nose at you as someone who is grossly inferior to me.

but you don't provide any actual details above what everyone already knows.

The message I posted here https://news.ycombinator.com/item?id=42557398 is excessively detailed.

What we did was put de-blobbed GrapheneOS on a compute board, put secure boot on another compute board, punt the radio onto a separate compute board, add a battery, and manage it all with a management board in a small backpack, with a USB touchscreen for user interface.

Then we productized it for select groups of people.

But, it's really not that complicated. Like it's really not. Many people have built these kinds of things before.

If you want to try to tell me that mindslight has a "provable track record" talking about this field, I have a very very hard time believing something like that because -- and I'm being honest here -- as any reasonable person will also conclude: his responses he has posted here are really fuckin' stupid.

This is exactly why there are some more "enterprise" machines out there that an arbitrary adversary with physical access can not "abruptly restart" from the outside.

It's a shame that popularly used OEMs still allow "abrupt restart" to be so easy.