Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.hardware > #3449 > unrolled thread
| Started by | Johnny <johnny@invalid.net> |
|---|---|
| First post | 2021-03-22 14:58 -0500 |
| Last post | 2021-03-24 11:46 -0700 |
| Articles | 10 on this page of 30 — 11 participants |
Back to article view | Back to comp.os.linux.hardware
Best Desktop Computer for Linux Mint Johnny <johnny@invalid.net> - 2021-03-22 14:58 -0500
Re: Best Desktop Computer for Linux Mint Bobbie Sellers <bliss@mouse-potato.com> - 2021-03-22 13:20 -0700
Re: Best Desktop Computer for Linux Mint Johnny <johnny@invalid.net> - 2021-03-22 15:46 -0500
Re: Best Desktop Computer for Linux Mint Zebee Johnstone <zebeej@gmail.com> - 2021-03-23 00:35 +0000
Re: Best Desktop Computer for Linux Mint Andrew <Doug@hyperspace.vogon.gov> - 2021-03-22 22:08 +0100
Re: Best Desktop Computer for Linux Mint Johnny <johnny@invalid.net> - 2021-03-22 16:20 -0500
Re: Best Desktop Computer for Linux Mint David Brown <david.brown@hesbynett.no> - 2021-03-23 08:30 +0100
Re: Best Desktop Computer for Linux Mint David Brown <david.brown@hesbynett.no> - 2021-03-23 08:22 +0100
Re: Best Desktop Computer for Linux Mint Scott Alfter <scott@alfter.diespammersdie.us> - 2021-03-24 16:24 +0000
Re: Best Desktop Computer for Linux Mint Henrik Carlqvist <Henrik.Carlqvist@deadspam.com> - 2021-03-24 20:43 +0000
Re: Best Desktop Computer for Linux Mint Marc Haber <mh+usenetspam1118@zugschl.us> - 2021-03-23 09:50 +0100
Re: Best Desktop Computer for Linux Mint David Brown <david.brown@hesbynett.no> - 2021-03-23 11:13 +0100
Re: Best Desktop Computer for Linux Mint Aragorn <thorongil@telenet.be> - 2021-03-23 11:59 +0100
Re: Best Desktop Computer for Linux Mint David Brown <david.brown@hesbynett.no> - 2021-03-23 15:07 +0100
Re: Best Desktop Computer for Linux Mint "David W. Hodgins" <dwhodgins@nomail.afraid.org> - 2021-03-23 13:19 -0400
Re: Best Desktop Computer for Linux Mint David Brown <david.brown@hesbynett.no> - 2021-03-24 10:04 +0100
Re: Best Desktop Computer for Linux Mint "David W. Hodgins" <dwhodgins@nomail.afraid.org> - 2021-03-24 05:36 -0400
Re: Best Desktop Computer for Linux Mint Marc Haber <mh+usenetspam1118@zugschl.us> - 2021-03-23 13:46 +0100
Re: Best Desktop Computer for Linux Mint David Brown <david.brown@hesbynett.no> - 2021-03-23 15:08 +0100
Re: Best Desktop Computer for Linux Mint Marc Haber <mh+usenetspam1118@zugschl.us> - 2021-03-23 16:30 +0100
Re: Best Desktop Computer for Linux Mint Henrik Carlqvist <Henrik.Carlqvist@deadspam.com> - 2021-03-23 19:40 +0000
Re: Best Desktop Computer for Linux Mint David Brown <david.brown@hesbynett.no> - 2021-03-24 10:12 +0100
Re: Best Desktop Computer for Linux Mint Henrik Carlqvist <Henrik.Carlqvist@deadspam.com> - 2021-03-24 20:55 +0000
Re: Best Desktop Computer for Linux Mint Andrew <Doug@hyperspace.vogon.gov> - 2021-03-24 11:31 +0100
Re: Best Desktop Computer for Linux Mint "David W. Hodgins" <dwhodgins@nomail.afraid.org> - 2021-03-24 11:20 -0400
Re: Best Desktop Computer for Linux Mint Johnny <johnny@invalid.net> - 2021-03-24 07:49 -0500
Re: Best Desktop Computer for Linux Mint Adrian Caspersz <email@here.invalid> - 2021-03-24 14:01 +0000
Re: Best Desktop Computer for Linux Mint Johnny <johnny@invalid.net> - 2021-03-24 10:02 -0500
Re: Best Desktop Computer for Linux Mint Scott Alfter <scott@alfter.diespammersdie.us> - 2021-03-24 16:05 +0000
Re: Best Desktop Computer for Linux Mint Bobbie Sellers <bliss@mouse-potato.com> - 2021-03-24 11:46 -0700
Page 2 of 2 — ← Prev page 1 [2]
| From | Henrik Carlqvist <Henrik.Carlqvist@deadspam.com> |
|---|---|
| Date | 2021-03-23 19:40 +0000 |
| Message-ID | <s3dg7m$hln$1@dont-email.me> |
| In reply to | #3458 |
On Tue, 23 Mar 2021 11:13:48 +0100, David Brown wrote: > There is nothing that a UEFI BIOS can do that a traditional BIOS > cannot, Yes it is. An UEFI BIOS is able to understand and modify contents on file systems on the computer. This in combination with the feature to be able to update the BIOS from software running in the computers operating system makes things interesting in a bad way. This is the kind of features that gives us persistent malware surviving reformatted and even repaced disks. The features are not only used by malware makers but has also been used by vendors like Lenovo for bloatware: https://www.techdirt.com/articles/20150812/11395231925/lenovo-busted- stealthily-installing-crapware-via-bios-fresh-windows-installs.shtml What did they call this? Secure boot? regards Henrik
[toc] | [prev] | [next] | [standalone]
| From | David Brown <david.brown@hesbynett.no> |
|---|---|
| Date | 2021-03-24 10:12 +0100 |
| Message-ID | <s3evpb$g6b$1@dont-email.me> |
| In reply to | #3465 |
On 23/03/2021 20:40, Henrik Carlqvist wrote: > On Tue, 23 Mar 2021 11:13:48 +0100, David Brown wrote: >> There is nothing that a UEFI BIOS can do that a traditional BIOS >> cannot, > > Yes it is. An UEFI BIOS is able to understand and modify contents on file > systems on the computer. First, let me repeat - there is nothing that the UEFI BIOS can do that another BIOS cannot. There is nothing hindering a non-UEFI BIOS being able to access files. A Coreboot BIOS, for example, has as much of a Linux system as you choose to compile into it. It is not UEFI - it does not provide the UEFI-specified services, or need the UEFI partition. Secondly, a UEFI BIOS cannot access files except on a very simplistic and limited filesystem (fat32). It can't work with files on NTFS, ext4, btrfs, raid, or anything else. > This in combination with the feature to be able > to update the BIOS from software running in the computers operating > system makes things interesting in a bad way. This is the kind of > features that gives us persistent malware surviving reformatted and even > repaced disks. The features are not only used by malware makers but has > also been used by vendors like Lenovo for bloatware: > > https://www.techdirt.com/articles/20150812/11395231925/lenovo-busted- > stealthily-installing-crapware-via-bios-fresh-windows-installs.shtml > > What did they call this? Secure boot? > Traditional BIOSes have been able to block writes to boot sectors (previous to that, boot sector viruses were "popular". The only virus I have ever had on a computer was a boot sector virus). And updates to BIOS were protected by "security by obscurity" - updates were so inconvenient that you didn't do it by mistake or malware. When you have unnecessarily features that are not used (and therefore people don't get familiar with them and spot flaws), and an overly complex design, then security failures are almost inevitable.
[toc] | [prev] | [next] | [standalone]
| From | Henrik Carlqvist <Henrik.Carlqvist@deadspam.com> |
|---|---|
| Date | 2021-03-24 20:55 +0000 |
| Message-ID | <s3g90e$910$2@dont-email.me> |
| In reply to | #3467 |
On Wed, 24 Mar 2021 10:12:10 +0100, David Brown wrote: > On 23/03/2021 20:40, Henrik Carlqvist wrote: >> On Tue, 23 Mar 2021 11:13:48 +0100, David Brown wrote: >>> There is nothing that a UEFI BIOS can do that a traditional BIOS >>> cannot, >> >> Yes it is. An UEFI BIOS is able to understand and modify contents on >> file systems on the computer. > > First, let me repeat - there is nothing that the UEFI BIOS can do that > another BIOS cannot. There is nothing hindering a non-UEFI BIOS being > able to access files. In theory no, but in practice a traditional BIOS has size limits. With UEFI the BIOS got bloated and with this bloat came both problems from complexity and insecurity by design. > A Coreboot BIOS, for example, has as much of a > Linux system as you choose to compile into it. It is not UEFI - it does > not provide the UEFI-specified services, or need the UEFI partition. Yes, I do not claim that UEFI is the only bloated BIOS. My intention was to compare UEFI with traditional (legacy) BIOS made to boot a DOS partition table with MBR. > Secondly, a UEFI BIOS cannot access files except on a very simplistic > and limited filesystem (fat32). It can't work with files on NTFS, ext4, > btrfs, raid, or anything else. This is true, but some operating systems will look for files on that partition and run them. > Traditional BIOSes have been able to block writes to boot sectors > (previous to that, boot sector viruses were "popular". The only virus I > have ever had on a computer was a boot sector virus). Yes, but a boot sector virus could be removed by replacing the drive or by simply overwriting the MBR. Malware which has gotten into your BIOS is a lot harder to get rid of. regards Henrik
[toc] | [prev] | [next] | [standalone]
| From | Andrew <Doug@hyperspace.vogon.gov> |
|---|---|
| Date | 2021-03-24 11:31 +0100 |
| Message-ID | <s3f4ds$a68$1@gioia.aioe.org> |
| In reply to | #3465 |
Henrik Carlqvist wrote: > On Tue, 23 Mar 2021 11:13:48 +0100, David Brown wrote: >> There is nothing that a UEFI BIOS can do that a traditional BIOS >> cannot, > > Yes it is. An UEFI BIOS is able to understand and modify contents on file > systems on the computer. This in combination with the feature to be able > to update the BIOS from software running in the computers operating > system makes things interesting in a bad way. This is the kind of > features that gives us persistent malware surviving reformatted and even > repaced disks. The features are not only used by malware makers but has > also been used by vendors like Lenovo for bloatware: > > https://www.techdirt.com/articles/20150812/11395231925/lenovo-busted- > stealthily-installing-crapware-via-bios-fresh-windows-installs.shtml > > What did they call this? Secure boot? > > regards Henrik > If you're worried about horrible things happening on your /boot/efi filesystem, may I suggest https://linuxconfig.org/intrusion-detection-systems-using-tripwire-on-linux I have used this in the distant past when in a corporate network where a sysadmin was known to have dubious morals and can say that you need to be very careful which filesystems you use this on - a "differences" report of half a million lines is useless for practical purposes, even /boot/efi is updated quite frequently with the distribution I use.
[toc] | [prev] | [next] | [standalone]
| From | "David W. Hodgins" <dwhodgins@nomail.afraid.org> |
|---|---|
| Date | 2021-03-24 11:20 -0400 |
| Message-ID | <op.00rl8qvua3w0dxdave@hodgins.homeip.net> |
| In reply to | #3469 |
On Wed, 24 Mar 2021 06:31:25 -0400, Andrew <Doug@hyperspace.vogon.gov> wrote: > If you're worried about horrible things happening on your /boot/efi > filesystem, may I suggest > https://linuxconfig.org/intrusion-detection-systems-using-tripwire-on-linux This isn't a discussion about the files on disk being changed. It's a discussion about the firmware being hacked, which would then make things like tripwire useless. The firmware runs before the os even starts. While uefi normally only includes code for working with vfat file systems, a hack of it could add code that works with other file systems too. Like the Intel Management engine, or the AMD Platform Security Processor, the uefi firmware has control before the os starts up so it can in theory include a remote access tool. Unlike the Intel Management engine, or the AMD Platform Security Processor, which are only found in server systems targeted at corporate or government users, the uefi firmware is also in all newer consumer devices. Tools like tripwire are helpful to identify changes made that the os can detect. It doesn't help with stealth root kits that get started before the os or tripwire starts. Regards, Dave Hodgins -- Change dwhodgins@nomail.afraid.org to davidwhodgins@teksavvy.com for email replies.
[toc] | [prev] | [next] | [standalone]
| From | Johnny <johnny@invalid.net> |
|---|---|
| Date | 2021-03-24 07:49 -0500 |
| Message-ID | <20210324074907.0e00304a@jspc> |
| In reply to | #3465 |
On Tue, 23 Mar 2021 19:40:38 -0000 (UTC) Henrik Carlqvist <Henrik.Carlqvist@deadspam.com> wrote: > On Tue, 23 Mar 2021 11:13:48 +0100, David Brown wrote: > > There is nothing that a UEFI BIOS can do that a traditional BIOS > > cannot, > > Yes it is. An UEFI BIOS is able to understand and modify contents on > file systems on the computer. This in combination with the feature to > be able to update the BIOS from software running in the computers > operating system makes things interesting in a bad way. This is the > kind of features that gives us persistent malware surviving > reformatted and even repaced disks. The features are not only used by > malware makers but has also been used by vendors like Lenovo for > bloatware: > > https://www.techdirt.com/articles/20150812/11395231925/lenovo-busted- > stealthily-installing-crapware-via-bios-fresh-windows-installs.shtml > > What did they call this? Secure boot? > > regards Henrik Thanks. I won't be buying a Lenovo.
[toc] | [prev] | [next] | [standalone]
| From | Adrian Caspersz <email@here.invalid> |
|---|---|
| Date | 2021-03-24 14:01 +0000 |
| Message-ID | <ic0v12F37kjU1@mid.individual.net> |
| In reply to | #3470 |
On 24/03/2021 12:49, Johnny wrote: >> What did they call this? Secure boot? >> >> regards Henrik > > Thanks. I won't be buying a Lenovo. > That was 2015, and Lenovo got rightly scolded. In 2021, crapware is free with Windows 10. You won't be running that. No, don't rule out Lenovo. They probably have the most Linux friendly kit out there, laptops and desktops, particularly in the second-hand ex-business (not consumer line) business. https://itsfoss.com/lenovo-linux-certified/ Whatever you are looking at (Dell/HP/Lenovo), try and find a hardware-maintenance manual for the product, an online community of upgraders for the product (maybe also linux users), youtube channels, and availability of spares and goodies on eBay. However, if you are into playing computer games, then go elsewhere. ex-Business line products won't have either the graphics or power supply support unless you bastardize a server or workstation machine. -- Adrian C
[toc] | [prev] | [next] | [standalone]
| From | Johnny <johnny@invalid.net> |
|---|---|
| Date | 2021-03-24 10:02 -0500 |
| Message-ID | <20210324100240.11843d88@jspc> |
| In reply to | #3471 |
On Wed, 24 Mar 2021 14:01:06 +0000 Adrian Caspersz <email@here.invalid> wrote: > On 24/03/2021 12:49, Johnny wrote: > > >> What did they call this? Secure boot? > >> > >> regards Henrik > > > > Thanks. I won't be buying a Lenovo. > > > > That was 2015, and Lenovo got rightly scolded. > > In 2021, crapware is free with Windows 10. You won't be running that. > > > No, don't rule out Lenovo. They probably have the most Linux friendly > kit out there, laptops and desktops, particularly in the second-hand > ex-business (not consumer line) business. > > https://itsfoss.com/lenovo-linux-certified/ > > Whatever you are looking at (Dell/HP/Lenovo), try and find a > hardware-maintenance manual for the product, an online community of > upgraders for the product (maybe also linux users), youtube channels, > and availability of spares and goodies on eBay. > > However, if you are into playing computer games, then go elsewhere. > ex-Business line products won't have either the graphics or power > supply support unless you bastardize a server or workstation machine. > I haven't decided yet which computer I will buy. I just want a newer one, I think this old HP came out in 2013. I've picked out one so far, it's a little over 3 years old. It only has 8GB of DDR4 memory, but I have 16 GB of DDR4 memory I can install. https://www.newegg.com/dell-optiplex-5050-business-desktops-workstations/p/1VK-0001-5JU87?Description=dell%20optiplex%205050&cm_re=dell_optiplex%205050-_-9SIAAJ2DBA8261-_-Product&quicklink=true I don't play computer games other than Freecell, and the old HP is fine for that.
[toc] | [prev] | [next] | [standalone]
| From | Scott Alfter <scott@alfter.diespammersdie.us> |
|---|---|
| Date | 2021-03-24 16:05 +0000 |
| Message-ID | <wrJ6I.31148$bL3.20701@fx10.iad> |
| In reply to | #3449 |
In article <20210322145810.4efb70c6@jspc>, Johnny <johnny@invalid.net> wrote: >I have always used HP computers, then I got one with UEFI settings >instead of a legacy BIOS. I didn't think I would ever get Linux Mint >installed on it. I finally did get it installed, but it was a pain. > >I would like to try another brand of computer, like Asus, Lenovo, Acer >or some other brand. What's wrong with EFI? It is different from working with an older BIOS-based system, but once you're only slightly familiar with it, it seems easier to deal with. I've installed Gentoo Linux on EFI systems ranging from a Dell PowerEdge R7515 on down to a Rock Pi X without any trouble to speak of. _/_ / v \ Scott Alfter (remove the obvious to send mail) (IIGS( https://alfter.us/ Top-posting! \_^_/ >What's the most annoying thing on Usenet?
[toc] | [prev] | [next] | [standalone]
| From | Bobbie Sellers <bliss@mouse-potato.com> |
|---|---|
| Date | 2021-03-24 11:46 -0700 |
| Message-ID | <s3g1dl$82c$1@dont-email.me> |
| In reply to | #3474 |
On 3/24/21 9:05 AM, Scott Alfter wrote: > In article <20210322145810.4efb70c6@jspc>, Johnny <johnny@invalid.net> wrote: >> I have always used HP computers, then I got one with UEFI settings >> instead of a legacy BIOS. I didn't think I would ever get Linux Mint >> installed on it. I finally did get it installed, but it was a pain. >> >> I would like to try another brand of computer, like Asus, Lenovo, Acer >> or some other brand. > > What's wrong with EFI? It is different from working with an older > BIOS-based system, but once you're only slightly familiar with it, it seems > easier to deal with. I've installed Gentoo Linux on EFI systems ranging > from a Dell PowerEdge R7515 on down to a Rock Pi X without any trouble to > speak of. > > _/_ > / v \ Scott Alfter (remove the obvious to send mail) > (IIGS( https://alfter.us/ Top-posting! > \_^_/ >What's the most annoying thing on Usenet? > Nothing at all wrong with EFI and it provides better partioning choices for users who need it. It is also capable of handling modern equipment much easier than when 80 GB IDE hard drives were the norm. When you have special needs for security then such a facility gives you the chance to have multiple encrypted partions and systems such as Split Linux which hids the actual OS from possibly interested parties. On my Amiga I had 9 partitions and one was the backup of the system and that was on a 4.3 GB hard drive. On my Dell 6520 I had multiple OSes and partitions with my base system having uefi, /boot, /, /var, /usr, /home and then for the rest of the systems maybe 2 partions each and up to at least 4 installs of various systems. That does not run like a charm but shows up the problems of that method especially with GRUB which each new install modifies. In addition those extra partitions may be filled with the data for various uses. For a lot of uses LiLo is adequate but no longer maintained as far as I know. But for modern and future systems EFI is far superior. bliss - “Nearly any fool can use a Linux computer. Many do.” After all here I am... -- bliss dash SF 4 ever at dslextreme dot com
[toc] | [prev] | [standalone]
Page 2 of 2 — ← Prev page 1 [2]
Back to top | Article view | comp.os.linux.hardware
csiph-web