Hacker News new | ask | show | jobs
by JCattheATM 370 days ago
> The open source feature of Secureboot is true only if you have replaced the laptop firmware with Coreboot, which is compatible only with few, mostly old, laptops.

Plenty of newer stuff that is explicitly open like the system 7 and framework stuff also.

> Even in that case, a laptop with Coreboot will still use closed-source components that cannot be trusted,

As does any solution relying on a BIOS.

> If someone steals the device, I cannot see any difference between our 2 setups.

In my setup, if the laptop is stolen, the thief is able to use a limited OS that give them all the functionality they would need while running a locator service in the background, allowing the hardware to be recovered, while preventing access to encrypted data.

It doesn't sound like your setup allows for that.

> However in the case that relies on the internal firmware and TPM to protect the keys, there are more sophisticated hardware attacks against the motherboard,

No matter what, using a BIOS makes you a lot more vulnerable than using any form of secure boot. It's a significantly more vulnerable standard.

1 comments

>> Even in that case, a laptop with Coreboot will still use closed-source components that cannot be trusted,

> As does any solution relying on a BIOS

Not true: https://news.ycombinator.com/item?id=44241911

lol, and you're back to indirectly referencing coreboot.
Yes, except the root of trust in my link is FLOSS.
So it is too with a FOSS secure boot implementation like verified boot.

Round and round we go....

Your setup is less secure. Period.

> Your setup is less secure. Period.

Tommy, is that you? https://forum.qubes-os.org/t/discussion-on-purism/2627/146

When you can figure out how to setup a foss secure boot implementation with verified boot, then maybe I'll consider your input on bootloader security worth considering.

Until then, I don't think it makes sense to continue this discussion. I assume you'll claim it isn't possible, but anyone who expends the slightest effort will see how far from reality that is.

Have a great day.