Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #59491

Re: Secure boot signing infrastructure - feedback request

From Tollef Fog Heen <tfheen@err.no>
Newsgroups linux.debian.kernel
Subject Re: Secure boot signing infrastructure - feedback request
Date 2017-11-24 21:00 +0100
Message-ID <uPsiJ-6Qw-7@gated-at.bofh.it> (permalink)
References (1 earlier) <uyFYJ-3Yt-9@gated-at.bofh.it> <uyJfZ-5Uo-9@gated-at.bofh.it> <uyKF3-74D-13@gated-at.bofh.it> <uzTPY-2RZ-21@gated-at.bofh.it> <uOLns-5ef-11@gated-at.bofh.it>
Organization Private

Show all headers | View raw


]] Ben Hutchings 

(Sorry for the massive Cc list, it'd be nicer if this could all just go
to -efi, but I don't know if everybody is subscribed to that list, so…)

> Sorry for taking so long to respond to this.
> 
> On Tue, 2017-10-10 at 20:36 +0200, Ansgar Burchardt wrote:
> > Ben Hutchings writes:
> > > On Mon, 2017-10-09 at 17:38 +0100, Steve McIntyre wrote:
> > > > On Mon, Oct 09, 2017 at 02:01:15PM +0100, Ben Hutchings wrote:
> > > 
> > > [...]
> > > > > It also appears to mean that buildds can get anything signed on demand
> > > > > with no human intervention at all, without all the checks that dak does
> > > > > on uploads.  This seems to be to substantially raise the risk of
> > > > > signing evil code and needing to revoke those signatures (or the
> > > > > signing key).
> > > > 
> > > > We spoke about this too. Source packages uploaded and eventually built
> > > > on the buildds already go through dak and wanna-build, for one. We
> > > > have to trust that mechanism already.
> > > 
> > > It's also audited - every upload is publicly logged, which makes it
> > > hard for an attacker to hide an evil upload.
> > 
> > Does anyone ever look at the upload history of buildds and audits them?
> 
> I don't know.  But as I understand it, nation-state attackers generally
> don't like to leave traces, so public logs can be a valuable deterrent.

We can easily make the signing logs public too, possibly with some sort
of time delay mechanism if needed for handling of embargoed security.

Also, while we don't need to solve it (yet), it would be nice if the
proposed solution we go for is able to solve the case of signing all
binaries in the archive (or at least don't make it impossible to do), if
we decide to do something like Matthew talks about in
https://debconf17.debconf.org/talks/174/ .

Cheers,
-- 
Tollef Fog Heen
UNIX is user friendly, it's just picky about who its friends are

Back to linux.debian.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Secure boot signing infrastructure - feedback request Helen Koike <helen.koike@collabora.com> - 2017-10-05 20:30 +0200
  Re: Secure boot signing infrastructure - feedback request Helen Koike <helen.koike@collabora.com> - 2017-10-09 03:20 +0200
  Re: Secure boot signing infrastructure - feedback request Ben Hutchings <ben@decadent.org.uk> - 2017-10-09 15:10 +0200
    Re: Secure boot signing infrastructure - feedback request Steve McIntyre <steve@einval.com> - 2017-10-09 18:40 +0200
      Re: Secure boot signing infrastructure - feedback request Julien Cristau <jcristau@debian.org> - 2017-10-09 18:50 +0200
      Re: Secure boot signing infrastructure - feedback request Ben Hutchings <ben@decadent.org.uk> - 2017-10-09 20:10 +0200
        Re: Secure boot signing infrastructure - feedback request Ansgar Burchardt <ansgar@debian.org> - 2017-10-13 00:10 +0200
          Re: Secure boot signing infrastructure - feedback request Helen Koike <helen.koike@collabora.com> - 2017-10-13 00:20 +0200
            Re: Secure boot signing infrastructure - feedback request Steve McIntyre <steve@einval.com> - 2017-10-31 17:00 +0100
              Re: Secure boot signing infrastructure - feedback request Helen Koike <helen.koike@collabora.com> - 2017-11-15 14:50 +0100
                Re: Secure boot signing infrastructure - feedback request Ben Hutchings <ben@decadent.org.uk> - 2017-11-23 00:20 +0100
                Re: Secure boot signing infrastructure - feedback request Steve McIntyre <steve@einval.com> - 2017-11-23 17:30 +0100
              Re: Secure boot signing infrastructure - feedback request Ben Hutchings <ben@decadent.org.uk> - 2017-11-23 00:10 +0100
            Re: Secure boot signing infrastructure - feedback request Ben Hutchings <ben@decadent.org.uk> - 2017-11-23 00:10 +0100
              Re: Secure boot signing infrastructure - feedback request Steve McIntyre <steve@einval.com> - 2017-11-23 17:30 +0100
          Re: Secure boot signing infrastructure - feedback request Ben Hutchings <ben@decadent.org.uk> - 2017-11-22 23:10 +0100
            Re: Secure boot signing infrastructure - feedback request Tollef Fog Heen <tfheen@err.no> - 2017-11-24 21:00 +0100
        Re: Secure boot signing infrastructure - feedback request Steve McIntyre <steve@einval.com> - 2017-10-13 00:50 +0200
          Re: Secure boot signing infrastructure - feedback request Ben Hutchings <ben@decadent.org.uk> - 2017-11-22 23:20 +0100

csiph-web