Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > aus.computers > #71467 > unrolled thread
| Started by | Keithr0 <nothing.to.see@here.com.au> |
|---|---|
| First post | 2024-11-28 21:55 +1000 |
| Last post | 2024-12-16 16:39 +1000 |
| Articles | 3 on this page of 43 — 8 participants |
Back to article view | Back to aus.computers
Why secure boot might be a good idea on your Linux machine Keithr0 <nothing.to.see@here.com.au> - 2024-11-28 21:55 +1000
Re: Why secure boot might be a good idea on your Linux machine not@telling.you.invalid (Computer Nerd Kev) - 2024-11-29 07:27 +1000
Re: Why secure boot might be a good idea on your Linux machine Keithr0 <nothing.to.see@here.com.au> - 2024-11-29 10:54 +1000
Re: Why secure boot might be a good idea on your Linux machine Keithr0 <nothing.to.see@here.com.au> - 2024-11-30 17:53 +1000
Re: Why secure boot might be a good idea on your Linux machine not@telling.you.invalid (Computer Nerd Kev) - 2024-12-01 06:43 +1000
Re: Why secure boot might be a good idea on your Linux machine Keithr0 <nothing.to.see@here.com.au> - 2024-12-02 21:31 +1000
Re: Why secure boot might be a good idea on your Linux machine Mighty Mouse <"squeak!"@thecheesefactory.com> - 2024-12-09 19:31 +1100
Re: Why secure boot might be a good idea on your Linux machine Keithr0 <nothing.to.see@here.com.au> - 2024-12-09 19:33 +1000
Re: Why secure boot might be a good idea on your Linux machine Daniel70 <daniel47@nomail.afraid.org> - 2024-12-10 00:22 +1100
Re: Why secure boot might be a good idea on your Linux machine Keithr0 <nothing.to.see@here.com.au> - 2024-12-10 20:36 +1000
Re: Why secure boot might be a good idea on your Linux machine Daniel70 <daniel47@nomail.afraid.org> - 2024-12-10 22:05 +1100
Re: Why secure boot might be a good idea on your Linux machine Mighty Mouse <"squeak!"@thecheesefactory.com> - 2024-12-11 00:38 +1100
Re: Why secure boot might be a good idea on your Linux machine not@telling.you.invalid (Computer Nerd Kev) - 2024-12-11 07:20 +1000
Re: Why secure boot might be a good idea on your Linux machine Mighty Mouse <"squeak!"@thecheesefactory.com> - 2024-12-18 09:43 +1100
Re: Why secure boot might be a good idea on your Linux machine Mighty Mouse <"squeak!"@thecheesefactory.com> - 2024-12-18 09:59 +1100
Re: Why secure boot might be a good idea on your Linux machine Computer Nerd Kev <not@telling.you.invalid> - 2024-12-18 11:32 +1000
Re: Why secure boot might be a good idea on your Linux machine Mighty Mouse <"squeak!"@thecheesefactory.com> - 2024-12-19 13:18 +1100
Re: Why secure boot might be a good idea on your Linux machine Computer Nerd Kev <not@telling.you.invalid> - 2024-12-19 13:34 +1000
Re: Why secure boot might be a good idea on your Linux machine Mighty Mouse <"squeak!"@thecheesefactory.com> - 2024-12-19 17:57 +1100
Re: Why secure boot might be a good idea on your Linux machine Mighty Mouse <"squeak!"@thecheesefactory.com> - 2024-12-19 18:22 +1100
Re: Why secure boot might be a good idea on your Linux machine Mighty Mouse <"squeak!"@thecheesefactory.com> - 2024-12-19 20:34 +1100
Re: Why secure boot might be a good idea on your Linux machine Mighty Mouse <"squeak!"@thecheesefactory.com> - 2024-12-20 12:26 +1100
Re: Why secure boot might be a good idea on your Linux machine not@telling.you.invalid (Computer Nerd Kev) - 2024-12-21 07:34 +1000
Re: Why secure boot might be a good idea on your Linux machine Mighty Mouse <"squeak!"@thecheesefactory.com> - 2024-12-21 12:30 +1100
Re: Why secure boot might be a good idea on your Linux machine not@telling.you.invalid (Computer Nerd Kev) - 2024-12-21 14:36 +1000
Re: Why secure boot might be a good idea on your Linux machine Mighty Mouse <"squeak!"@thecheesefactory.com> - 2024-12-21 18:18 +1100
Re: Why secure boot might be a good idea on your Linux machine Mighty Mouse <"squeak!"@thecheesefactory.com> - 2024-12-21 22:32 +1100
Re: Why secure boot might be a good idea on your Linux machine not@telling.you.invalid (Computer Nerd Kev) - 2024-12-22 07:55 +1000
Re: Why secure boot might be a good idea on your Linux machine Mighty Mouse <"squeak!"@thecheesefactory.com> - 2024-12-23 11:14 +1100
Re: Why secure boot might be a good idea on your Linux machine Computer Nerd Kev <not@telling.you.invalid> - 2024-12-23 16:48 +1000
Re: Why secure boot might be a good idea on your Linux machine Mighty Mouse <"squeak!"@thecheesefactory.com> - 2024-12-23 12:12 +1100
Re: Why secure boot might be a good idea on your Linux machine Computer Nerd Kev <not@telling.you.invalid> - 2024-12-23 16:52 +1000
Re: Why secure boot might be a good idea on your Linux machine ng <ng@ng.com> - 2024-12-29 14:33 +0000
Re: Why secure boot might be a good idea on your Linux machine ng <ng@ng.com> - 2025-01-03 03:43 +0000
Re: Why secure boot might be a good idea on your Linux machine MightyMouse <"squeak!"@thecheesefactory.com> - 2025-01-05 18:43 +1100
Re: Why secure boot might be a good idea on your Linux machine MightyMouse <"squeak!"@thecheesefactory.com> - 2025-01-05 18:43 +1100
Re: Why secure boot might be a good idea on your Linux machine not@telling.you.invalid (Computer Nerd Kev) - 2024-12-10 08:05 +1000
Re: Why secure boot might be a good idea on your Linux machine Mighty Mouse <"squeak!"@thecheesefactory.com> - 2024-12-10 10:23 +1100
Re: Why secure boot might be a good idea on your Linux machine not@telling.you.invalid (Computer Nerd Kev) - 2024-12-11 07:28 +1000
Re: Why secure boot might be a good idea on your Linux machine Keithr0 <nothing.to.see@here.com.au> - 2024-12-12 21:41 +1000
Re: Why secure boot might be a good idea on your Linux machine noel <deletethis@invalid.lan> - 2024-12-13 07:08 +1000
Re: Why secure boot might be a good idea on your Linux machine not@telling.you.invalid (Computer Nerd Kev) - 2024-12-13 07:19 +1000
Re: Why secure boot might be a good idea on your Linux machine Keithr0 <nothing.to.see@here.com.au> - 2024-12-16 16:39 +1000
Page 3 of 3 — ← Prev page 1 2 [3]
| From | noel <deletethis@invalid.lan> |
|---|---|
| Date | 2024-12-13 07:08 +1000 |
| Message-ID | <675b50e6$1@news.ausics.net> |
| In reply to | #71488 |
On Thu, 12 Dec 2024 21:41:07 +1000, Keithr0 wrote: It may be difficult to come up with something that targets all > distros, but attacking a single distro would not be too difficult. It's been done, to ubuntu, only this year (or was it late last year now) but I find mainly those who are windows converts use that. Mind you, I'd go further and say, all bad actors need to do is get deeper into systemd, because it in and of itself, is nothing more than a virus, doing more damage to linux than the folks at Redmond ever could... IMHO. systemd wants to dictate to you how you will use the OS, ring a bell? (cough windows cough), and debian weenors are now more enshirned into it, since as of release 12.x they have moved to using systemd log shit, which makes debugging a nightmare, traditional log files are no more on debian 12 - unless you spend the time to be rid of that nonsense (and no its not just a case of indstlaling rsyslog or whatever flavour you like). fortuately I'm left with only one debian POS, as its now required for FreePBX - well if you want to get any support out of them, and even today sangoma still havent got asterisk and freepbx running as smooth as Centos, I suggested what if I port it to slackware, they said you're on your own we will not provide any support or help, be it our misconfig or a factual bug, tickets will be closed as "unsupported os" systemd so much more complexity, a service file of dozen lines to do what we can do in slackware for example, in 3, thats of course once you find the offending systemd service file At that point, you only have to deal with idiots who shouldnt have root. If they have a user a/c that gets r00ted, you wipe them out and re-add them, after a stern talk hehe. *friends don't let friends use systemd based distros* (hrrmmm should add a webster entry request... " systemd - A Linux system dictator ")
[toc] | [prev] | [next] | [standalone]
| From | not@telling.you.invalid (Computer Nerd Kev) |
|---|---|
| Date | 2024-12-13 07:19 +1000 |
| Message-ID | <675b537d@news.ausics.net> |
| In reply to | #71488 |
Keithr0 <nothing.to.see@here.com.au> wrote: > On 11/12/2024 7:28 am, Computer Nerd Kev wrote: >> Mighty Mouse <"squeak!"@thecheesefactory.com> wrote: >>> Computer Nerd Kev wrote: >>>> Mighty Mouse <"squeak!"@thecheesefactory.com> wrote: >>>>> Computer Nerd Kev wrote: >>>>>> Since you're pretty stuffed once a hacker has root access anyway, >>>>>> Secure Boot never seemed worth the added complexity to me, but >>>>>> that's a matter of opinion. >>>>> what happens if they get root access? >>>> They can read any file and install/change whatever software they >>>> like, same as you can yourself. A non-root user on a Linux system >>>> is more limited, although exactly how limited depends on the >>>> permissions granted to that user (for a user running high-risk >>>> things like Web server processes, usually very few). >>> >>> thanks, that explains it. I assume reinstalling Linux fixes the problem >> >> Usually, unless it's something new which installs to the UEFI >> firmware like some viruses have done on Windows. >> > See the first message in this thread, it has already been done. As it happens that article has been revised now to point out that this hasn't already been done, at least not by that particular Linux bootkit. > There is nothing special about Linux that would prevent the same > thing being done. Yep, once the attacker has found a way to get root access there. I wasn't implying otherwise. -- __ __ #_ < |\| |< _#
[toc] | [prev] | [next] | [standalone]
| From | Keithr0 <nothing.to.see@here.com.au> |
|---|---|
| Date | 2024-12-16 16:39 +1000 |
| Message-ID | <lsa092Fec9cU1@mid.individual.net> |
| In reply to | #71490 |
On 13/12/2024 7:19 am, Computer Nerd Kev wrote: > Keithr0 <nothing.to.see@here.com.au> wrote: >> On 11/12/2024 7:28 am, Computer Nerd Kev wrote: >>> Mighty Mouse <"squeak!"@thecheesefactory.com> wrote: >>>> Computer Nerd Kev wrote: >>>>> Mighty Mouse <"squeak!"@thecheesefactory.com> wrote: >>>>>> Computer Nerd Kev wrote: >>>>>>> Since you're pretty stuffed once a hacker has root access anyway, >>>>>>> Secure Boot never seemed worth the added complexity to me, but >>>>>>> that's a matter of opinion. >>>>>> what happens if they get root access? >>>>> They can read any file and install/change whatever software they >>>>> like, same as you can yourself. A non-root user on a Linux system >>>>> is more limited, although exactly how limited depends on the >>>>> permissions granted to that user (for a user running high-risk >>>>> things like Web server processes, usually very few). >>>> >>>> thanks, that explains it. I assume reinstalling Linux fixes the problem >>> >>> Usually, unless it's something new which installs to the UEFI >>> firmware like some viruses have done on Windows. >>> >> See the first message in this thread, it has already been done. > > As it happens that article has been revised now to point out that > this hasn't already been done, at least not by that particular > Linux bootkit. > >> There is nothing special about Linux that would prevent the same >> thing being done. > > Yep, once the attacker has found a way to get root access there. > I wasn't implying otherwise. > Open source seems to be getting more and more vulnerable to supply chain exploits. Miscreants have realised that they can become maintainers and slip exploits into items that are dependencies for other applications. At least one instance has been detected, who knows how many more are out there.
[toc] | [prev] | [standalone]
Page 3 of 3 — ← Prev page 1 2 [3]
Back to top | Article view | aus.computers
csiph-web