Path: csiph.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail From: Keithr0 Newsgroups: aus.computers Subject: Re: Why secure boot might be a good idea on your Linux machine Date: Mon, 16 Dec 2024 16:39:31 +1000 Lines: 39 Message-ID: References: <6748e05b@news.ausics.net> <674b78d6@news.ausics.net> <675769a6@news.ausics.net> <6758b282@news.ausics.net> <675b537d@news.ausics.net> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Trace: individual.net TMa/rb+VAsChkzVJvz2zxAKUNFAM1SC26nfMUlhgzUQ01IAtl5 Cancel-Lock: sha1:4I0xFnJ+t9s5s73zL1ZCPf7y8Tc= sha256:VHQkKgtlV5/eBlsyPWYFySlqoDuBO4mwHOnkG6Mw6SM= User-Agent: Mozilla Thunderbird Content-Language: en-US In-Reply-To: <675b537d@news.ausics.net> Xref: csiph.com aus.computers:71494 On 13/12/2024 7:19 am, Computer Nerd Kev wrote: > Keithr0 wrote: >> On 11/12/2024 7:28 am, Computer Nerd Kev wrote: >>> Mighty Mouse <"squeak!"@thecheesefactory.com> wrote: >>>> Computer Nerd Kev wrote: >>>>> Mighty Mouse <"squeak!"@thecheesefactory.com> wrote: >>>>>> Computer Nerd Kev wrote: >>>>>>> Since you're pretty stuffed once a hacker has root access anyway, >>>>>>> Secure Boot never seemed worth the added complexity to me, but >>>>>>> that's a matter of opinion. >>>>>> what happens if they get root access? >>>>> They can read any file and install/change whatever software they >>>>> like, same as you can yourself. A non-root user on a Linux system >>>>> is more limited, although exactly how limited depends on the >>>>> permissions granted to that user (for a user running high-risk >>>>> things like Web server processes, usually very few). >>>> >>>> thanks, that explains it. I assume reinstalling Linux fixes the problem >>> >>> Usually, unless it's something new which installs to the UEFI >>> firmware like some viruses have done on Windows. >>> >> See the first message in this thread, it has already been done. > > As it happens that article has been revised now to point out that > this hasn't already been done, at least not by that particular > Linux bootkit. > >> There is nothing special about Linux that would prevent the same >> thing being done. > > Yep, once the attacker has found a way to get root access there. > I wasn't implying otherwise. > Open source seems to be getting more and more vulnerable to supply chain exploits. Miscreants have realised that they can become maintainers and slip exploits into items that are dependencies for other applications. At least one instance has been detected, who knows how many more are out there.