Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > gnu.hurd.help > #358

Re: Combining Hurd and Qubes OS for security reasons? Possible?

Path csiph.com!xmission!news.glorb.com!usenet.stanford.edu!not-for-mail
From Arne Babenhauserheide <arne_bab@web.de>
Newsgroups gnu.hurd.help
Subject Re: Combining Hurd and Qubes OS for security reasons? Possible?
Date Wed, 23 Dec 2015 09:20:37 +0100
Lines 49
Approved help-hurd@gnu.org
Message-ID <mailman.431.1450858855.843.help-hurd@gnu.org> (permalink)
References <CAB=Lj3T9dABDCnfiPFmui45WdZSVvpGs6rMX=PBVR6O94Es-Ug@mail.gmail.com> <CAB=Lj3T9C+fMQm=dLy6OV2zwBE2DpX61+9KV6QCveRjiSABMOQ@mail.gmail.com> <20151222173416.GA13375@shattrath>
NNTP-Posting-Host lists.gnu.org
Mime-Version 1.0
Content-Type multipart/signed; boundary="nextPart6629813.RHXznUULL1"; micalg="pgp-sha256"; protocol="application/pgp-signature"
X-Trace usenet.stanford.edu 1450858856 12782 208.118.235.17 (23 Dec 2015 08:20:56 GMT)
X-Complaints-To action@cs.stanford.edu
Cc Samuel Thibault <samuel.thibault@gnu.org>, David Renz <sun.kisses.horizon@gmail.com>, Richard Braun <rbraun@sceen.net>
To help-hurd@gnu.org
Envelope-to help-hurd@gnu.org
User-Agent KMail/4.14.8 (Linux/4.1.12-gentoo; KDE/4.14.8; x86_64; ; )
In-Reply-To <20151222173416.GA13375@shattrath>
X-Provags-ID V03:K0:7mZsTttGbsPvc/gMVeP8b/QFJxZmwfoAMyMDRAhr7mvwAX93Fp7 S66EKyaDHT5Lubv/Nvj7nvf2iNc2u9D3nh2bmE096ElWXZ9A/0znLnZFxMdvMg4QZ0uGXWX moWQetRiRkUNPrZhEuAVVnLYEkjI2KGXOGuS8gBzEvQaRheDBFY7eqNPDYndL3Wlr01J1Mj nu7mL5Mg5WqBCiEA3p72Q==
X-UI-Out-Filterresults notjunk:1;V01:K0:yY8JEUA8UHg=:Kpro5d4K+DpJU+jETRaIz2 dL59f26wgyiP4aKUWIqV2gya2BSJse3GNm3rl+zkdXHX02oVRJ8rGM3I6QCBJzjsbmtNnuHaj fBCR0En/8UwbzK+i+Ne/O0qb8kkvMvmWcxN3qnrFk+yRRYSGYEleGGTgGkIKYpnvGwx3Py+QW mjyRqxRYnWqJXFNjWp+XcKAwu4AZFmG8ytDRaEsK9Z/obbfLE9dTF5mg3Z8jpGPJubwNT9XGu J8lR+pbPG8rRlmWcHLl+h7nebchIHTZoFiceK9YuaVexRmu4jZA1MkGQ793Pk9Kc92rmcqSgO Gi6mpBeVX+/EqGNgnHBfZjEZdjuL/lVKvRZZgHeYPHJmpJIGHiaObprQRGj1LhESBUQ2wbM6u aJdPmah4ZshqYBEdchi3GiGCvy63fr0v5PaC6u4CZzopK3ikjp9l7m0qyVm5h3L3m7cUOkFD2 WXqyB8CIbPnCc30+dZ7dOEBl4xh1Bx+TddvboJxbLDt2CroiHpfkVQ1GQO6Jcl4sJf+VZj16o 8NkAm5Tpii5Pm4Ap94uq32AzJbFIw5iu0TwFYO5EnZvw0ZVj7EW0qhKdqZp18afqXJUOLU1bR AiMWuak3WwznW5kL5Sy5/nc0wTsFPpmuReWv9sGNtCWW7UR98c1WULPHHsRMccco5AU+rYCr1 gDgWxUL8uMKZTNjjIz4MVmtCHSPAF1aT5RFuPeUGKQcNK9i9UekmF93oS8zA+LsKsva0phH+z d0Zya+3vrCcqgojl9LgMxUxZOCsrePproglHzqUKtAIH/LlzIH2P3awjbjM=
X-detected-operating-system by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic]
X-Received-From 212.227.15.3
X-BeenThere help-hurd@gnu.org
X-Mailman-Version 2.1.14
Precedence list
List-Id Users list for the GNU Hurd <help-hurd.gnu.org>
List-Unsubscribe <https://lists.gnu.org/mailman/options/help-hurd>, <mailto:help-hurd-request@gnu.org?subject=unsubscribe>
List-Archive <http://lists.gnu.org/archive/html/help-hurd>
List-Post <mailto:help-hurd@gnu.org>
List-Help <mailto:help-hurd-request@gnu.org?subject=help>
List-Subscribe <https://lists.gnu.org/mailman/listinfo/help-hurd>, <mailto:help-hurd-request@gnu.org?subject=subscribe>
Xref csiph.com gnu.hurd.help:358

Show key headers only | View raw


[Multipart message — attachments visible in raw view] - view raw

Am Dienstag, 22. Dezember 2015, 18:34:16 schrieb Richard Braun:
> On Tue, Dec 22, 2015 at 06:05:07PM +0100, David Renz wrote:
> > Unless one would be using an open-hardware/openBIOS based system, I don't
> …
> Not being able to easily update firmwares isn't acceptable nowadays.
> Having code running on the hardware is actually perfectly acceptable,
> as long as you are aware and accept that these are small systems of
> their own.

Taking out all the details in-between it sounds like you pretty much
agree (at least on the big picture). If the code on the hardware is a
small system of its own, then it should be free software, which means
it would run openBIOS.

> In the case of ACPI though, I'm not sure whether IOMMUs actually
> enforce access verification in system management mode, but if it
> does, a properly implemented multi-server system with IOMMU
> hardware should be able to provide a high level of security
> despite those shortcomings.

So you mean that with the Hurd it might be possible to get a trusted
system despite having some unfree components?

Best wishes,
Arne

Back to gnu.hurd.help | Previous | Next | Find similar


Thread

Re: Combining Hurd and Qubes OS for security reasons? Possible? Arne Babenhauserheide <arne_bab@web.de> - 2015-12-23 09:20 +0100

csiph-web