‹ BackHN Continuity

Thread

Upgrade your desktop: Ubuntu 26.04.1 LTS is now available

80 points · 103 comments · d99kris

  1. bArray · · focus · HN ↗
    > TPM-backed full-disk encryption is now generally available in the Ubuntu installer. By tying encryption to the TPM security chip, disk encryption is bound to a specific device, significantly raising the bar for physical access attacks while improving the user experience.

    That's great, but they are also intending to comply with the OS-level age verification [1]. Initial implementations will somehow be privacy protecting, but eventually the temptation to tie a specific person to an OS fingerprint will become too great.

    [1] <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;LinusTechTips&#x2F;comments&#x2F;1rk4fj7&#x2F;ubuntu_is_planning_to_comply_with_age&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;LinusTechTips&#x2F;comments&#x2F;1rk4fj7&#x2F;ubun...

    1. Buttons840 · · focus · HN ↗
      How long until I can selectively tell certain websites I&#x27;m a child so they stop showing me ads?

      They wanted the personal computer to store and report personal information. I hope they have their best surprised faces ready for when computers report what the owner wants them to report.

      1. teekert · · focus · HN ↗
        That is only possible when you really are the owner. And the amount of device out there in the world where people really are the owner is rather small. (Just the Linux desktops and the GrapheneOS smartphones, etc.)
        1. Retr0id · · focus · HN ↗
          You are not quite the owner on GrapheneOS either, because of Android Key Attestation (which has functionality analogous to desktop TPMs). If you re-unlock your bootloader (say, to run a custom build of GrapheneOS), attestation will snitch on you and the subset of apps that use key attestation to require a locked bootloader and&#x2F;or enforce an AVB key allowlist will not work properly. This is a very small subset of apps currently, but I don&#x27;t see it getting any smaller.
          1. sliken · · focus · HN ↗
            GrapheneOS does everything and more for key attestation, allowing security sensitive applications to test the integrity of the device. Sadly some apps like google wallet not only check for attestation, but check if Google&#x27;s signed it. Which is against the idea of attestation in the first place.

            So google&#x27;s tap to pay doesn&#x27;t work, but others do, like garmin pay. Random bank apps are hit and miss.

            1. Retr0id · · focus · HN ↗
              &gt; GrapheneOS does everything and more for key attestation

              Right, that&#x27;s the problem, in my opinion. I&#x27;m not referring to the apps that require Google&#x27;s keys only, I&#x27;m referring to the ones that allow GrapheneOS keys too. If you use one of these apps, you can use vanilla GrapheneOS builds, but you cannot run your own self-signed builds.

              You are gaining freedom relative to running Google&#x27;s OS, but you are still not free to further modify the software running on your own device.

              Apps that require &quot;integrity&quot; should monitor their own integrity only, they should not attempt to infer the integrity of their environment.

              1. sliken · · focus · HN ↗
                Trick is there&#x27;s no integrity without the OS. Cheats can ruin games, keyloggers can record passwords, music&#x2F;movies can be stolen, bitcoins can be stolen, etc.
                1. Retr0id · · focus · HN ↗
                  Attestation does not solve this.
                  1. sliken · · focus · HN ↗
                    How so? Seems like it&#x27;s a pretty big step in the right direction, sure an attested phone is going to be much harder to compromise than one with custom os, custom kernel, and a user with root.
                    1. Retr0id · · focus · HN ↗
                      Attestation only detects user-initiated &quot;compromises&quot; like unlocking the bootloader and flashing a custom ROM. It does not detect exploitation.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.