Bootstrapping a slightly more secure laptop [video]
media.ccc.de
media.ccc.de
I think I've seen this before in an HPC context. But they've build a firmware distribution called Heads. It boots using coreboot then fires up a Linux kernel from flash.
The kernel is then used as a second stage bootloader. It takes about 2 seconds to get Linux booted from flash.
They can then boot the system OS, optionally using kexec to smoothly transition to the system kernel.
Very neat! Along the way they've also done other important work, like put together a minimal firmware for the Management engine (a second CPU in Intel system with its own OS, and many many issues).
The biggest problem here is same issue that coreboot has. Coreboot support is really limited. I think it down supports Lenovo X220s, but late time I looked not much modern hardware.
I thought that management engine CPU was still a black box, and the best anyone has done is neuter the firmware running there by judiciously zeroing bits out.
It is possible to install your own version of Linux too!
Then you can validate the signed token, and if everything is correct you can use the TPM value to decrypt the harddisk.
Right now I am using my remembered password plus static password mode of my Yubikey to have a fake 2FA decryption requirement on boot but UAF/U2F would be way cooler.
It there something wrong with this idea?
I am working on setting up a system with a YubiKey 4 in this way. Apple FDE can accept a certificate for verification. Or simply the password.
I haven't set up LUKS like this in a long, long time. But I will get there soon..
Please don't post on HN to ask or tell us something (e.g. to ask us
questions about Y Combinator, or to ask or complain about moderation).
If you want to say something to us, please send it to hn@ycombinator.com.
But the title of the talk is actually "Bootstraping [sic] a slightly more secure laptop." Look at the first slide.