User: Password:
|
|
Subscribe / Log in / New account

SUSE and Secure Boot: The Details (SUSE Blog)

SUSE and Secure Boot: The Details (SUSE Blog)

Posted Aug 12, 2012 13:41 UTC (Sun) by HelloWorld (guest, #56129)
In reply to: SUSE and Secure Boot: The Details (SUSE Blog) by geofft
Parent article: SUSE and Secure Boot: The Details (SUSE Blog)

It's easy to make them type something like debian-project.org. or ubuntu-os.com or whatever.


(Log in to post comments)

SUSE and Secure Boot: The Details (SUSE Blog)

Posted Aug 12, 2012 21:29 UTC (Sun) by dlang (subscriber, #313) [Link]

just ubuntu.org instead of ubuntu.com is easy enough (it's a mistake I make about half the time anyway)

SUSE and Secure Boot: The Details (SUSE Blog)

Posted Aug 12, 2012 23:59 UTC (Sun) by geofft (subscriber, #59789) [Link]

That still requires a fairly targeted attack -- you have to MITM the installation instructions and the ISO download, such that they access your text and your bootloader instead of the real one, and you have to do this while they're attempting to download and install a new OS. (And if you can do this MITM, you can as easily trojan the text instructions to say "go turn Secure Boot off", which is something lots of legitimate small distros will say.)

In other words, it's perfectly fine to accept that this attack exists. It still helps people from being infected with boot-sector viruses when they're not reinstalling their OS, which is the goal of this process. In general, people do not switch operating systems all the time; at most they tend to do so once or twice. Closing an existing vulnerability all the time except for during OS install is still a benefit.

SUSE and Secure Boot: The Details (SUSE Blog)

Posted Aug 17, 2012 14:48 UTC (Fri) by pjones (subscriber, #31722) [Link]

Not really, no - you make /dozens/ of sites like this. It's not a targeted attack - it's agriculture.


Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds