Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #264355 > unrolled thread
| Started by | Albretch Mueller <lbrtchx@gmail.com> |
|---|---|
| First post | 2023-12-06 23:30 +0100 |
| Last post | 2023-12-08 01:00 +0100 |
| Articles | 14 — 5 participants |
Back to article view | Back to linux.debian.user
ToG Linux (first draft of a RFC) ... Albretch Mueller <lbrtchx@gmail.com> - 2023-12-06 23:30 +0100
Re: ToG Linux (first draft of a RFC) ... Andy Smith <andy@strugglers.net> - 2023-12-07 02:30 +0100
Re: ToG Linux (first draft of a RFC) ... Albretch Mueller <lbrtchx@gmail.com> - 2023-12-07 08:20 +0100
Re: ToG Linux (first draft of a RFC) ... Arno Lehmann <al@its-lehmann.de> - 2023-12-07 10:50 +0100
Re: ToG Linux (first draft of a RFC) ... Albretch Mueller <lbrtchx@gmail.com> - 2023-12-09 10:20 +0100
Re: ToG Linux (first draft of a RFC) ... Albretch Mueller <lbrtchx@gmail.com> - 2023-12-09 12:30 +0100
Re: ToG Linux (first draft of a RFC) ... Arno Lehmann <al@its-lehmann.de> - 2023-12-09 15:00 +0100
Re: ToG Linux (first draft of a RFC) ... Greg Wooledge <greg@wooledge.org> - 2023-12-09 15:20 +0100
Re: ToG Linux (first draft of a RFC) ... John Hasler <john@sugarbit.com> - 2023-12-09 15:30 +0100
Re: ToG Linux (first draft of a RFC) ... Albretch Mueller <lbrtchx@gmail.com> - 2023-12-09 20:10 +0100
Re: ToG Linux (first draft of a RFC) ... Albretch Mueller <lbrtchx@gmail.com> - 2023-12-09 23:40 +0100
Re: ToG Linux (first draft of a RFC) ... John Hasler <john@sugarbit.com> - 2023-12-09 15:30 +0100
Re: ToG Linux (first draft of a RFC) ... Albretch Mueller <lbrtchx@gmail.com> - 2023-12-07 17:00 +0100
Re: ToG Linux (first draft of a RFC) ... Albretch Mueller <lbrtchx@gmail.com> - 2023-12-08 01:00 +0100
| From | Albretch Mueller <lbrtchx@gmail.com> |
|---|---|
| Date | 2023-12-06 23:30 +0100 |
| Subject | ToG Linux (first draft of a RFC) ... |
| Message-ID | <HI8yZ-bOG0-15@gated-at.bofh.it> |
ToG Linux ("Touch of God" (no blasphemy intended) a la Michelangelo's
"The Creation of Adam", with one of the poetic connotations being, to
make best use of what you know to be certain, what "you can touch"
(can exclusively reach with certainty), is readily available in your
immediacy (before the physical reality of fields was understood,
Leibniz made fun of Newton's "actions at a distance", of which Newton
himself admitted not to know its origin and nature ...))
This would be a first draft about what could be considered a poor-man
Debian Live air-gap running instance. I post it here because Debian is
definitely my favorite distro (and many other are based on it), the
deb live and blends mailing lists are mostly about specific changes to
their project and I am talking about general topics relating to
securing a Debian Linux running instance in a relatively straight
forward way based on options which are already available. No fanciness
or "conceptual demands"! Nothing new under the sun! It is more of a
„Deutsches Eck” kind of thing, making things confluent to make good of
them.
Some of the ideas have nothing to do with Debian per se, but
objectives which conceptual ecosystem aims at being able to use
computers with some of that thing they used to call "privacy", at the
very least less exposure. Most of the measures are procedural and
physical (involving hardware). Using just software would just be an
illusive waste of time.
~
0. Objectives:
0.1) even though by their very nature OSs', applications, network-
and/or IO-enabled computers can't possibly be secure, any malicious
software which manage to get in your system would be mindlessly erased
simply by a less than a minute reboot (only that would keep "hackers"
away, they need persistence and they know they would be exposing their
rear end to the four winds and that you won't have to spend your mind
on worries and/or your hard earned money on "virus scanners", "malware
detectors", ...);
0.2) you may be able to and should use the same computer in both:
exposed, and "air-gapped" mode;
0.3) ToG would require just some disciplined and prudent exercise of
your exposed activities, (if any) near to zero comma nada monetary
investment;
0.4) ToG would let its user base have -some- healthy and aware
tranquility of mind when it comes to safety and "privacy";
0.5) the use of a package extensions phase during the boot process,
makes blends unnecessary, since you would enhance the functionality of
your initial Debian Live DVD during boot up in whichever way you want
and even use other supported architecture*.
*:
0.5)* multi-session DVDs for various architectures?
0.5)* generally speaking people using certain applications (say
eclipse or Wazuh unified XDR and SIEM protection framework) would have
a better sense of where the configuration and work files are kept.
~
1) What you will need:
1.1) Debian Live on a DVD[-R|+R] write-once and finalize disk (you
can't physically write onto) (alternatively USB pen drives could be
used, but are not recommended, they are not simple "WYSWYG" things (a
USB pen drive can be a RF device in ways you can't simply tell apart
from regular ones) and most (all?) breaks into air-gap systems have
been through misuse of USB pen drives)*
1.2) a "package extensions" USB pen drive (where you would keep extra,
specific packages you need, not included in §1.1) and a lokal web
references file;
1.3) a computer, you own*, which:
1.3.1) BIOS doesn't include networking, is open source (could be
"trusted and checked") and which binaries you can linearize and dump
in full as a file*;
1.3.2) BIOS lets you choose the boot device;
1.3.3) is not powered, not connected to the Internet (either as part
of a wired or wireless network);
1.4) you will have a hard drive for your own your data which you never
connect to the Internet*.
*:
1.1)* an 8 cm (3.1 inches) DVD could be used which would easily fit in
your shirt's front pocket including the §1.2 USB pen drive, with the
most basic functionality.
1.3)* if you don't own the computer you are using, you will use the
Debian Live DVD as such without extra extensions automatic fanciness
and there will still be the option to update §1.2 for the new
architecture and Linux version/distribution, but it must be done on
the box you own which is the one with allows you access to the §1.2
strategy.
1.3.1)* Is there such a "safe BIOS"? Could you follow a physically
safe procedure around this? Could you: a) dump the BIOS data onto a
file? b) blank and reset the BIOS?, c) import a "new" binary and check
it?
1.4)* why aren't hard drives being produced with a physical/mechanical
switch to enable them to read data into or NOT?
1.4)* which HAL (Hardware AnaLyzer) techniques are used to check the
hardware inside hard disk drives and computers?
~
2) GRUB boot up Procedure (boot loaders' moment!):
2.1) insert Debian Live DVD;
2.2) power on computer;
2.3) select DVD as starting device;
2.4) as part of a secure boot procedure, at the grub start up options
prompt, run some code to dump BIOS as HEX file, which sha256sum is
then used to mount a USB pen drive via --uuid and to decrypt your
package extensions USB pen drive (§1.2);
2.5) boot continues*; ...
2.6) based on the combination of: a) architecture, b) Live DVD (which
could be multi-session for different architectures?), c) a list of
needed utilities and applications in your package extensions USB pen
drive, there will be:
2.6.2) some utilities which may come as part of the DVD;
2.6.3) other which will have to be installed with packages already in
the extension USB pen drive;
2.6.3) if some needed packages included in the list of extensions is
not included in the pen drive:
2.6.3.1) those packages will be listed;
2.6.3.2) some installation script will be generated for you and
dropped in §1.2 which you would then run automatically becoming a
permanent update once you boot using your home computer;
2.6.3.3) a copy of the script will be left in your $HOME folder for
you to run right after you expose your computer during this sessions
2.7) sudo umount §1.2 and unplug it before exposing your computer*
*:
2.4)* keep that pen drive with you at all times, in your set of keys
if necessary (go pee before pluggin it in, do not leave your computer
unattended!)
2.5)* where are the knoppix-like boot options: "toram",
"tohd=<partition>", "fromhd=<partition>", "myconf=<...>", "home=<...>"
in Debian Live?
https://en.wikibooks.org/wiki/Knowing_Knoppix/Knoppix_boot_options
The "toram" bootup option would make your instance even more
unhackable since all RAM content will be unpowered, blank when the
computer is turned off. These days even a $50 tablet comes with 16Gb
RAM.
2.7)* internal check as part of the boot process to continue only
after §1.2 has been physically unplugged?
~
3) Exposed mode:
3.1) expose your computer by first physically/mechanically connecting
the networking hardware you use (wired connections are always faster,
right?);
3.2) run the necessary firmware (optimal option)*, if not
automatically detected;
3.3) if §2.6.3.3 installation script exists, run it to download,
install and save installed packages;
3.4) include versions of firefox and chromium browser (brave has HAR
and TOR capabilities) run through selenium automation to:
3.4.1) parse/rewrite every HTML page based on its XPaths to choose
what would reach your field of view;
3.4.2) keep track of data which have already been downloaded (so their
link color will be changed) based on the lokal web reference file from
the unexposed run*;
3.4.3) storage space is insanely cheap, anyway: as you "browse the
web" (by downloading files to your computer) you keep them in a
structured way in your hard drive's fs with paths more or less
matching the URLs and URL <-> lokal Path ref. Tables (instead of using
"download" subdirectory for all files)
*:
3.2)* necessary installation script and networking libraries will be
left in $HOME by §1.2 (ideally networking should be taken out of the
Linux kernel)
3.4.1)* of crucial importance, not only to clear your way of all that
google goo, farting images and javascript cr@p with pop ups telling
you "they care about your privacy", showing you how much better would
be dumping your sex partner and developing a crush on some amine
picture, ... but also javascript is the main compromising attack
vector used by that good for nothing Vladimir Putin and all IT
companies are in bed with him anyway, as are (Victoria) Santa Nuland
("of the freedom loving cookies" (as she was canonized)), Ursula von
der Leyen ("Queen of the EU royal garden"), ...
3.4.1)* after the parsing/XPath rewriting phase, downloaded pages
would be kept as part of Korpus to be shared among users belonging to
a friends of friends network (most of us have our ways to perceive and
make sense of outer reality. Even though they might not "influence"
you, farting images, annoying pop-up windows and such things get in
your way in the way that you may not be scared of a barking dog, but
the constant barking definitely taxes your mind and ultimately makes
you waste time, anyway).
3.4.1)* to what extent should generated content be "engaged". Is,
"yes, suring!" them enough?
3.4.1)* et 3.4.2)* (Selenium-linked) "lokal web" strategy whichever
browser is being automated would route through, handle data using the
four identifying coordinates: ("site + URL Path", "page", "link
trajectory", "XPath within page") in order to look up an index to run
a command object which cleanses that page segment ...
3.4.1)* et 3.4.2)* (Selenium-linked) Declaring on your settings that
all sites or one in particular may not run javascript is way too
coarse and breaks functionality.
3.4.1)* et 3.4.2)* (Selenium-linked) Broker all settings regardless of
the browser used via Selenium.
3.4.2)* changing all links to the local option in a disk partition
mounted as --read-only if available?
3.4.3)* all links of downloaded and kept pages and data must be
relative, the external drive must be mounted via --uuid and the path
to the lokal web directory should be part of some environment
variable.
3.4.3)* some textual data such a pdf files may contain full (not
relative) links, which should be extracted and downloaded (if data
linked doesn't exist, try the way back machine, ... ).
~
4) Unexposed mode (one way transfer strategy to save your data before
shuting down your computer):
4.1) disconnect the exposed computer from the Internet by removing
firm/software;
4.2) physically/mechanically remove your wired or wireless USB dongle*;
4.3) if post-installation script exists and you are on your home box,
prompt telling user to insert §1.2 to save the downloaded installation
packages;
4.4) rename §1.2 based on size, the number of lines and sha256sum;
4.5) in order to transfer data from the exposed configuration to the
unexposed, external drive, you will:
4.5.1) mount your external hard drive §1.4;
4.5.2) right after mounting it, run a script to check the physical
health of the disk (smartctl, xfs repair if you are running XFS, keep
a dmesg diff from before and after the disk was mounted);
4.5.3) transfer delta of data via rsync;
4.5.4) recreate list of lokal (append new records to) web references
based on §4.5.3 delta;
4.5.5) transfer new file with lokal web references to §1.2;
*:
4.2)* should you inforced that the Internet connection is not
available before continuing?
4.5.4)* should also there be a full check option double checking that
"2+2=4" to be run once in a while?
4.5.5)* metadata in the name of the file: size, lines and sha256sum
~
5.) shutdown*
5.1) run file integrity checks, keeping diffs of last exposed sessions ...
5.2) shutdown
5.3) power off
*:
5)* regular shutdown procedures and checks are also part of securing
your instances. "Hackers" will hate that since they existentially need
persistence in your box and for you to be "visual", passive and
innocent about it.
~
6. ToG's shortcomings:
6.1) laptop and tablets these days come without a DVD caddy;
6.2) Most applications assume (and demand even during their installation!) that:
6.2.1) your computer is connected to the Internet; and
6.2.2) you are installing applications on your hard drive; so,
settings should be permanent ...
6.3) some cookies and other data/session tracking bs you may want to keep.
6.4) you should not buy your computer over the Internet (at least not
as an "all-in-one" PC) at least I know well about one of my best known
hells, in the U.S. the federal postal service works as a nation-wide
black chamber!
*:
6.1)* you will have to keep one in your backpack inside of a
protective box or use a partition of your USB pendrive to boot your
computer (ideally if some sort of knoppix-like fromhd boot option is
used, there should be an option to check the size, type and sha*sum of
the iso)
6.2.2)* et 6.3)*: think of settings in browsers, startup conf files in
Eclipse or a regular text editor, browsers' add ons, ... : running fs
deltas right before exposing and right before shutdown would make
obvious which work and configuration files may belong to which version
of an applications and where they should be placed during the next
boot, they should be saved in §1.2 and replaced after each reboot.
~
7. Other security measures:
7.1) keep your computer in a Faraday Cage ideally grounded through
both a ground plug of your electrical power outlet and some metal such
as a digging bar deeply pushed into the ground and connected with a
conducting wire to your Faraday cage;
7.2) noise the immediate vicinity of your environment with random,
stochastic audible noise, ultra sound and EM variations in order to
avoid, degrade tempesting;
7.3) read off and write on paper your must sensitive data (passwords,
...) and your most important train of thoughts;
7.4) why aren't there disks and pen drives with a switch to
physically/mechanically disable the writing of data onto them?
7.5) from such apparently innocuous data such as your "finger"
(keystroke patterns) to your search terms, should ToG include active
noising options? (you mind a term search, while your browser somewhat
predictively (within a narrative, initially and afterwards) does some
search terms on antonyms and marginal senses based on word lists,
thesauri and ludwig.guru patterns by itself which don't reach your
field of view)
7.6) they say "life is a b!tch" and some add the coda "that is why I
like it so much" as "we the people" do in places such a Cuba and did
East Germany (and who would have thought that "'the' land of 'the'
'free' ..." would make you think of what goes on in Cuba and went on
East Germany as benign, less perniciously consequential, much less
all-encompassing?) creating a degree of noise around you (relatively
loud music while you talk on the phone, work office kinds of
background noises, ...) would cost nothing and be "healthy" to your
mind and body.
You may ask me questions or suggest options on my wordpress page:
https://ergosumus.wordpress.com/2023/12/06/tog-touch-of-god-linux-first-draft-of-a-rfc/
or right here via the mailing list.
thank you,
lbrtchx
[toc] | [next] | [standalone]
| From | Andy Smith <andy@strugglers.net> |
|---|---|
| Date | 2023-12-07 02:30 +0100 |
| Message-ID | <HIbnb-bQkx-1@gated-at.bofh.it> |
| In reply to | #264355 |
Hi, On Wed, Dec 06, 2023 at 10:25:55PM +0000, Albretch Mueller wrote: > You may ask me questions or suggest options on my wordpress page: > > https://ergosumus.wordpress.com/2023/12/06/tog-touch-of-god-linux-first-draft-of-a-rfc/ This page doesn't seem to exist (yet?). I looked at the root of the web site and the most recent post was from February 2022. Thanks, Andy -- https://bitfolk.com/ -- No-nonsense VPS hosting
[toc] | [prev] | [next] | [standalone]
| From | Albretch Mueller <lbrtchx@gmail.com> |
|---|---|
| Date | 2023-12-07 08:20 +0100 |
| Message-ID | <HIgPT-bTKN-5@gated-at.bofh.it> |
| In reply to | #264371 |
Oh, well! "My paranoia" as Greg would say ;-) Yes, they removed it again! I have no effing idea why (other than messing with me) You could hopefully see my back and forths with them: https://wordpress.com/forums/topic/how-long-does-it-take-for-a-new-post-to-become-active/ Let me resume fighting them to see if they allow my post (they hadn't, then they did for a while, ...) I will keep you all posted. Given the options I hope our community doesn't get too upset about us going about our initial brainstorming here. lbrtchx
[toc] | [prev] | [next] | [standalone]
| From | Arno Lehmann <al@its-lehmann.de> |
|---|---|
| Date | 2023-12-07 10:50 +0100 |
| Message-ID | <HIjb4-bV2Y-17@gated-at.bofh.it> |
| In reply to | #264381 |
Hello, it's quite interesting that you use a platform such as wordpress, running code you can not control, to discuss such matters. Wouldn't it be more reasonable to self host, using a hoster providing decent privacy and aonymity or a technology such as Tor? Given the amount of time and effort you put into your draft, that would not be a big overhead, I think. It would, however, make it clearer that you actually mean it. Also, what I know about secure, air-gapped systems, can be summarized quite easily: - You can not use the same hardware air gapped and non air gapped. - Maintaining such systems is a pain. - There are no shortcuts. Small anecdote: A colleague recently visited a US agencies secure site to help them with some software deployment. He could bring one DVD-R, not -RW, there. No electronic equipment. There are no USB keys, portable disks, or dual-booting devices repeatedly crossing the boundaries there. In particular, there are no exceptions. What you bring in is thoroughly examined and stays in. All your fancy ideas seem to be about bridging the gap. This will not create security. Cheers, Arno -- Arno Lehmann IT-Service Lehmann Sandstr. 6, 49080 Osnabrück
[toc] | [prev] | [next] | [standalone]
| From | Albretch Mueller <lbrtchx@gmail.com> |
|---|---|
| Date | 2023-12-09 10:20 +0100 |
| Message-ID | <HJ1F7-cm55-1@gated-at.bofh.it> |
| In reply to | #264383 |
On 12/7/23, Arno Lehmann <al@its-lehmann.de> wrote: > it's quite interesting that you use a platform such as wordpress, > running code you can not control, to discuss such matters. I was just brainstorming, dumping a stream of consciousness with a relatively comprehensive outline of the main ideas. > Wouldn't it be more reasonable to self host That will definitely happen at some point. I will have to test first the Linux initialization process (it’s runlevels) and how to make it dance together with GRUB nicely (no mysteries whatsoever there). > ... using a hoster providing > decent privacy and aonymity or a technology such as Tor? I am not into protagonism and that is not my main line of research, occupation. I would like to culture (invite more like-minded people to own) that open source project. Anyone could take over hosting it (I would pay for the first two years) and anything we do we would openly (well, almost! ;-)). As they say: true security, privacy, ... can not be hidden. All we do and say we would to the four winds. Once it is vetted we could even ask nicely for it to be included as part of the Debian or some other hosting. > Also, what I know about secure, air-gapped systems, can be summarized > quite easily: > > - You can not use the same hardware air gapped and non air gapped. I beg to differ and at the end of the day this is something that can be physically/technically proved. Basically, how could you hack a computer which you booted without a physical networking interface and (part of the objectives) without loading the networking capabilities from the kernel by exploiting Linux' runlevels? All you would need to do is automating updates to that configuration. > - Maintaining such systems is a pain. Well, not really! Booting a Debian Live DVD doesn't take more time than booting Windows (from scratch) and the whole idea of using a package extensions USB pen drive would automate updates. This basically is all there is to maintaining it. You would be basically making use of the BIOS and RAM of a computer (you don't even need to own), you would keep the whole OS and all extras you need in your shirt's front pocket. If they mess with the BIOS you will notice it because the thing will not work and it would report the BIOS change and exactly how, what the difference is and for basic physical reasons you can't infect a computer's RAM. > - There are no shortcuts. Well, no! ... and this is a good thing! We both, "hackers" and "we the people", have to follow step by step procedures (what Ancient Greek thinkers called "techne" and later we meant by "functions" up to Descartes, before all that non-sensical "black box", I/O mindset took over), what makes the difference is "the touch of God" and that no one can take away from you that you could take care of your own security, privacy (as existential philosophers would say: "absolutely no one, nothing can take away your freedom"). Notice that I am not just talking about computer soft and hardware. I got my education as a theoretical Physicist (basically a double-major in Physics and Math) an der TU Dresden, so I tend to see, understand every through its physics. Experiment: 1) use a hermetic metal (not plastic, looking like metal!) box (one of those they use for candies) 2) turn on your cell phone and carefully put it inside (making sure it stays on) 3) close the metal box 4) right in front of that box place a call to your own phone using another one. * since EM waves can't reach your phone it would not only be functionally off the grid, but off the confines of the universe! and "Vladimir Putin" couldn't do sh!t about it! Isn't that cool!?!?! Now, doesn't it make it even cooler that you can do such thing without spending one cent? > Small anecdote: A colleague recently visited a US agencies secure site > to help them with some software deployment. He could bring one DVD-R, > not -RW, there. No electronic equipment. Well, yes! and how would those kinds of anecdotes speak against a "touch of God"? As anyone could see you could even run a network of detached computers without networking interfaces in a "touch of God" kind of way, some sort of "leased One-time pad touches of God" specifically for each, all coordinated through and which data/information would end up in a kind of "server", you could even use cell phones to do such thing ... lbrtchx
[toc] | [prev] | [next] | [standalone]
| From | Albretch Mueller <lbrtchx@gmail.com> |
|---|---|
| Date | 2023-12-09 12:30 +0100 |
| Message-ID | <HJ3GV-cngS-5@gated-at.bofh.it> |
| In reply to | #264471 |
On 12/9/23, Albretch Mueller <lbrtchx@gmail.com> wrote: > As anyone could see you could even run a network of detached > computers without networking interfaces in a "touch of God" kind of > way, some sort of "leased One-time pad touches of God" specifically > for each, all coordinated through and which data/information would end > up in a kind of "server", you could even use cell phones to do such > thing ... I could even envision industries around such specifications. The only reason why such things haven’t happened (would not ever happen?) is because police, politicians and IT companies (which these days are all the same) want to run society as if we were all rats in a maze they control real time in a predictive and cross correlating way in which everything is ephemeral to "we the people" while they keep a click by click, keystroke by keystroke, breath by breath, ... data Doppelgänger of each of us. Something "my paranoia" noticed as part of the Snowden revelations which IMO hasn’t been aired, questioned, discussed enough was that the NSA, as part of their "all tangible things" doctrine, was most interested in people’s medical records. Why?!? Why would "they" care about people’s health? Isn’t the safety and betterment of society what they should be interested in? To top it all "we the people" didn’t get the extent to which they were making fun of us when they said that: "what matters is how we use that information, not that we collect it"!!! This is how the world we are living in looks like: // __ 36C3 - The sustainability of safety, security and privacy: https://www.youtube.com/watch?v=2m5EMkVTydI (7:35) Internet of things or -Internet of Targets- (8:15) just as a car has got about 50 computers in it (11:20) hospital safety usability failures kill about 2000 people a year in the UK, just about car accidents (and he was just talking about impedance in the GUIs! not even about "errare humanum est") (12:30) some dude manage to gain access to 450,000 active pace makers over wifi (15:20) modern cars have about 10 radio frequency interfaces (23:20) initially light bulbs could be on for more than a century, ... these days companies make it from almost impossible to illegal to fix things in order to make money ... ~ At some point it all became so unbelievable, out of it all weird that I had to take as some sarcastic theatrics. Like when he showed hospital rooms and the number of network-enabled, RF devices in it. Since things happen for a reason, as part of explaining why Anderson could have at the very least asked why this is all happening) lbrtchx
[toc] | [prev] | [next] | [standalone]
| From | Arno Lehmann <al@its-lehmann.de> |
|---|---|
| Date | 2023-12-09 15:00 +0100 |
| Message-ID | <HJ626-covB-5@gated-at.bofh.it> |
| In reply to | #264471 |
Hello, On 09.12.23 at 10:13, Albretch Mueller wrote: > On 12/7/23, Arno Lehmann <al@its-lehmann.de> wrote: >> it's quite interesting that you use a platform such as wordpress, >> running code you can not control, to discuss such matters. > > I was just brainstorming, dumping a stream of consciousness with a > relatively comprehensive outline of the main ideas. Your paranoia needs an adjustment, because the above is what would make you targetable. ... >> - You can not use the same hardware air gapped and non air gapped. > > I beg to differ and at the end of the day this is something that can > be physically/technically proved. It has been proven. ... > Well, not really! Booting a Debian Live DVD doesn't take more time > than booting Windows (from scratch) and the whole idea of using a > package extensions USB pen drive would automate updates. This > basically is all there is to maintaining it. No. > You would be basically > making use of the BIOS and RAM of a computer You can not trust those. ... > As anyone could see you could even run a network of detached > computers without networking interfaces in a "touch of God" kind of > way, At this point it becomes quite clear that we have a misunderstanding at a very low level. Sentences like "run a network of ... computers without networking interfaces" are something I can not really grasp with the facilities I have. Cheers, Arno -- Arno Lehmann IT-Service Lehmann Sandstr. 6, 49080 Osnabrück
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <greg@wooledge.org> |
|---|---|
| Date | 2023-12-09 15:20 +0100 |
| Message-ID | <HJ6lr-coRb-3@gated-at.bofh.it> |
| In reply to | #264476 |
On Sat, Dec 09, 2023 at 02:50:16PM +0100, Arno Lehmann wrote: > On 09.12.23 at 10:13, Albretch Mueller wrote: > > As anyone could see you could even run a network of detached > > computers without networking interfaces in a "touch of God" kind of > > way, > > At this point it becomes quite clear that we have a misunderstanding at a > very low level. Sentences like "run a network of ... computers without > networking interfaces" are something I can not really grasp with the > facilities I have. Is he simply talking about sneakernet? A human administrator, whom I imagine to be the "god" in this scenario, walks around and room and types things on each computer as needed? What I don't understand is what these computers would be *doing*. Why does he need them at all? If he needs them, why does he need them to be detached from each other and from the rest of the world? The only things I can imagine are: * Calculating something that takes a long time to calculate. Maybe the problem can be trivially parallelized, in such a way that he can type the necessary parameters for each piece of the calculation on each node. Obviously it would be better if the nodes were networked to each other, instead of requiring manual collation of the results, but we've already established that the OP is insane. * Tools in the creation of some kind of work of art (visual, musical, etc.). A computer runs whatever software is used in this creative endeavor. At the end, a file is created, and this is copied onto removable media, which is then sent to a publisher. I don't see why he would need multiple computers in this scenario, unless he's got many projects going on simultaneously, and he wants one computer dedicated to each project. Whatever he's doing, I'm confident he won't tell us, or at least not in a way I'll be able to understand.
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <john@sugarbit.com> |
|---|---|
| Date | 2023-12-09 15:30 +0100 |
| Message-ID | <HJ6v7-coUb-1@gated-at.bofh.it> |
| In reply to | #264478 |
Greg writes: > Is he simply talking about sneakernet? A human administrator, whom I > imagine to be the "god" in this scenario, walks around and room and > types things on each computer as needed? Carrying removable media around. -- John Hasler john@sugarbit.com Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | Albretch Mueller <lbrtchx@gmail.com> |
|---|---|
| Date | 2023-12-09 20:10 +0100 |
| Message-ID | <HJaS5-crCN-7@gated-at.bofh.it> |
| In reply to | #264479 |
On 12/9/23, Greg Wooledge <greg@wooledge.org> wrote: >> On 09.12.23 at 10:13, Albretch Mueller wrote: >> > As anyone could see you could even run a network of detached >> > computers without networking interfaces in a "touch of God" kind of >> > way ... Thank you. I should have more clearly stated that those computing devices would go each about their particular business situationally in an air-gapped mode to then each go about their "collective intelligence" on a separate computer, a "server" of sorts. > What I don't understand is what these computers would be *doing*. Why > does he need them at all? If he needs them, why does he need them to > be detached from each other and from the rest of the world? These days, everything from microwave ovens to pacemakers are computing devices, but why should they be wifi-enabled? People don't seem to even realize that since the 1990's they have been driving computers on wheels. Then you hear that Vladimir Putin assassinated Michael Hastings for saying the same Joe Biden said only two decades before; you hear targeted individuals talking about of smoke rings (something that can't happen in nature by itself) to then hear about COVID-19 and how it was all started in China by some dissident "freedom-loving" bats, ... I even heard once as part of those marginal comments you hear which make you go like, say what?, that courtesy of U.S. tax payers the CIA was giving money to Ukrainian people but in order to get it they had to use their cell phones ;-) Think monitoring devices in hospitals, schools, power plants, ... I once heard that some "intelligence department" knew the grounding truth about some matter which happened in some remote place in Russia, because they had been monitoring the cell phones of not only "we the people", but even the police and, of course, when you hear such thing, since neither Physics nor "God" have "blue-eyed sons" (contrary to what some Israelis/Jewish people may think) or as they say "what is good for the goose is good for the gander", that also means that "the Chinese", "Russians", ... are able to do the same thing (of course, in their case they do it "because they hate freedom"). Now, imagine that at least the police would use a "ToG network" (to call it something) without any networking capabilities on a hard- and software level (just the necessary functionality, for example, passively getting GPS coordinates for which you don't need the whole networking stack) for their computing devices with a One-Time pad lease for the session they will be using it (and they would be physically powered for the amount of time they need to be used) which they must relinquish after each day of work to their base and which data would be encrypted (reusing the initial OTP) in ways that only the server which leased the OTP would be able to decrypt. Think of how they hacked the enigma machine and how Nazis suspected such a thing to have happened: https://en.wikipedia.org/wiki/Erhard_Maertens What could those "freedom hating" Chinese, "what the heck is freedom" Russians, all those "intelligence departments", ... do about any of it? > The only things I can imagine are ... > Whatever he's doing, I'm confident he won't tell us, or at least not in > a way I'll be able to understand. I explained the basic idea to a friend over the phone and clarified to him a number of doubts he had about it. He got it. He also realized that it wasn't much of a hassle, really. And he told me that I come up with such ideas because I have been forced to look at reality from a different point of view. In a Hegelian, karmic way it is a good thing that people looking at reality from different vantage points can talk to one another, even though, as they say, "misunderstanding is as mutual as love should be". No XY problem whatsoever, and I am not trying to hide anything from anyone (whatever "hiding", "privacy", ... could possibly mean these days). As Mike Rogers (of Pink Floyd fame) said when he was being accused of being a racist, anti-zionist or a zionist, (or whatever he was accused of), ...: "if I am, at the very least, I should be conscious of it". Keeping an external drive you never connect to the Internet could be understood as a sneakernet aspect of it. lbrtchx
[toc] | [prev] | [next] | [standalone]
| From | Albretch Mueller <lbrtchx@gmail.com> |
|---|---|
| Date | 2023-12-09 23:40 +0100 |
| Message-ID | <HJe9j-cttt-9@gated-at.bofh.it> |
| In reply to | #264487 |
On 12/9/23, Albretch Mueller <lbrtchx@gmail.com> wrote: > the CIA was giving money to Ukrainian people but in > order to get it they had to use their cell phones ;-) which (cell phones) they would also get "for free", mind you. And well ..., yes, even if you remove the networking hard and software, all RF devices need are electrons moving around in ways you can control and encode. Some time ago, I heard the expected news that they had managed to sandwich a RF circuitry on the layers of a chip! So, expect for everybody to start making their own chips at least for their most critical infrastructure! There will however always be physical ways to hack a hack. Imagine a bugged cell phone, you could always physically extend the functionality you need and keep the cell phone itself encased in a Faraday cage at all times. lbrtchx
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <john@sugarbit.com> |
|---|---|
| Date | 2023-12-09 15:30 +0100 |
| Message-ID | <HJ6v7-coUb-3@gated-at.bofh.it> |
| In reply to | #264476 |
Arno writes: > At this point it becomes quite clear that we have a misunderstanding > at a very low level. Sentences like "run a network of ... computers > without networking interfaces" are something I can not really grasp > with the facilities I have. You could run a slow network by mailing removable media around. In the early days Australia was on Usenet by way of airmailed taps. Then there's https://www.rfc-editor.org/rfc/rfc2549. Though consider: the earliest computer viruses were transmitted by floppy disk... -- John Hasler john@sugarbit.com Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | Albretch Mueller <lbrtchx@gmail.com> |
|---|---|
| Date | 2023-12-07 17:00 +0100 |
| Message-ID | <HIoX7-bYy9-13@gated-at.bofh.it> |
| In reply to | #264381 |
BTW, except for the GRUB/boot loading phase and its possible useful aspects relating to ToG-L (which I haven't found the time to study), I would say that 80%+ of the whole project I have already implemented with my lousy bash scripts skills and in java/GRAALVM as a first "proof of concept" and of the rest of it I have kept a thoroughgoing functional mental map. I have had to fight such issues for a long time and I initially thought of such things as ad hoc momentary solutions to be able to use the Internet, but at some point I started to think of it in an articulate and comprehensive way. > 2.5)* where are the knoppix-like boot options: "toram", > "tohd=<partition>", "fromhd=<partition>", "myconf=<...>", "home=<...>" > in Debian Live? We all know that a DVD caddy could be easily bugged as well (the USPS keeps stocks of all kinds of equally looking things which are bugged) and a DVD caddy is more of a mechanical, more power consuming thing, so it would be ideal to go the knoppix-like "toram" way. Knoppix these days is based a debian, so figuring out the grub hack to pass start up arguments to the kernel at boot time shouldn't be difficult. You would also be freeing the DVD port in case you need it. > 6.1)* you will have to keep one in your backpack inside of a > protective box or use a partition of your USB pendrive to boot your > computer (ideally if some sort of knoppix-like fromhd boot option is > used, there should be an option to check the size, type and sha*sum of > the iso) "bootfrom" would be also nice (I think in knoppix you can even combine the "bootfrom=<...>.iso" and "toram" start up options!). These days it doesn't matter much because you could use WSL (Windows Subsystem for Linux), but for whatever reason you may want to just use Linux. > ... that thing they used to call "privacy". I am old enough to remember the times in which telling someone that: "you care about their privacy" would have been taken as an odd joke. It would tacitly mean that -you have no privacy whatsoever-! Privacy is one of those things you would have to take care of yourself! (ToG-L would enable "we the people" to do so) In some European countries not just the government has implanted chips in military personnel, but your boss would make it a precondition to be hired even though it doesn't relate to your job description in the least! "We the people" would get chipped just to be part of a dance club! Some government have had ideas about chipping everyone which makes you wonder if people have started to lose their senses "in the end of times" ... Einstein who made his main occupation the mathematically measurable aspect of the it, mind you, said: "two things are infinite: the universe and human stupidity; and I'm not sure about the universe". I am not trying to be persuasive anyone. I actually think in the times we are living things have gotten more than half way off for way too long and we, scientists, tech monkeys and Mathematicians could and should inform "we the people" and help them more actively have their stand on, way out of such issues. lbrtchx
[toc] | [prev] | [next] | [standalone]
| From | Albretch Mueller <lbrtchx@gmail.com> |
|---|---|
| Date | 2023-12-08 01:00 +0100 |
| Message-ID | <HIwrD-c30v-1@gated-at.bofh.it> |
| In reply to | #264355 |
Hopefully finally! We should brainstorm our initial thoughts about it there and once we could envision some completion and continuing hope to it, we can move it into a formal github open source project: https://ergosumus.wordpress.com/2023/12/07/tog-linux-first-draft-of-a-rfc/ lbrtchx
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web