Android and ChromiumOS are likely the most trustable computing platforms out there; doubly so for Android running on Pixels. If you don't prefer the ROM Google ships with, you can flash GrapheneOS or CalyxOS and relock the bootloader.
Pixels have several protections in place:
- Hardware root of trust: This is the anchor on which the entire TCB (trusted computing base) is built.
- Cryptographic verification (verified boot) of all the bootloaders (IPL, SPL), the kernels (Linux and LittleKernel), and the device tree.
- Integrity verification (dm-verity) of the contents of the ROM (/system partition which contains privileged OEM software).
- File-based Encryption (fscrypt) of user data (/data partition where installed apps and data go) and adopted external storage (/sdcard); decrypted only with user credentials.
- Running blobs traditionally run in higher exception levels (like ARM EL2) in a restricted, mutually untrusted VM.
- Continued modularization of core ROM components so that they could be updated just like any other Android app, ie without having to update the entire OS.
- Heavily sandboxed userspace, where each app has very limited view of the rest of the system, typically gated by Android-enforced permissions, seccomp filters, selinux policies, posix ACLs, and linux capabilities.
- Private Compute Core for PII (personally identifiable information) workloads. And Trusty Execution Environment for high-trust workloads.
This is not to say Android is without exploits, but it seems it is most further ahead of the mainstream OSes. This is not a particularly high bar because of closed-source firmware and baseband, but this ties in generally with the need to trust the hardware vendors themselves (see point #1).
If history is of any guide Android and ChromiumOS likely still have many critical bugs the public does not know about yet.
Sadly the only choice is to burn extra ram to give every security context a dedicated kernel and virtual machine. Hypervisors are the best sandbox that exists anchored down to a hardware IOMMU.
QubesOS being VM based is thus the best effort secure workstation OS that exists atm. SpectrumOS looks promising as a potential next gen too.
I define the network access for each VM in a spreasheet (local services and Internet horizon), which then gets translated into firewall rules. I can simultaneously display multiple web browsers, each with a different network nym (casual browsing, commercial VPN'd, TOR, etc).
The downsides include needing an ethernet cable on my laptop (latency), and that this setup isn't great at going mobile. Eventually I'll get around to setting up a medium-trust laptop that runs a web browser and whatnot directly (while not having access to any keys to the kingdom), one of these days real soon now.
Which brings me to the real downside is the work required to administer it - you already have to be in the self-hosting game. This is where an out-of-the-box solution could excel. Having recently become a NixOS convert, SpectrumOS looks very interesting!
Just for interest sake, is Linux better or worse than MacOS, iOS and Windows at this?
One issue is that software has vulnerabilities and bugs. I’m not talking about the software that users run in sandboxes environments. I’m talking about the sandboxes environments. I’m talking about cryptography implementations. I’m talking about the firmware running in the “trusted” hardware.
The other major issue is as you alluded to: the need to trust vendors and hardware. Without protection and monitoring at the physical level, the user has no way to verify the operation of the giant stack of technology designed to “protect them”. Without the ability to verify operations, how is the user to trust anything? Why do companies tell users to “trust them” without any proof they are trustworthy?
This may seem like a minor point, but this is really the crux of the issue. Building this giant house of cards on top of a (potentially) untrustworthy hardware root of trust does not buy anyone anything. Certainly it does not buy “security”.
Large companies and nation states are the most likely adversaries one wants to be wary of these days (e.g. journalists, whistleblowers, etc.). What good does the technology do them if the supply chain is compromised or vendors are coerced to insert backdoors? These are the threats that actually face people concerned about security, not whether or not their executables are run in a sandboxed VM or not. Great, you’ve stopped the adversary from inserting malicious code into your device after purchase. Good thing for them, they did it prior to or during manufacture.
The technology you alluded to above is mainly useful for protecting company IP from end users, IMO. That’s how I’ve mainly seen it used, and the marketing of “security for the user” is a gimmick to justify the process.
EDIT: I forgot to mention this entire class of security issue since I am used to working on air gapped systems. I don’t care if you are operating in a sandboxed VM with a randomized MAC over a VPN over Tor. If you’re communicating with any other device over the Internet, you have to trust every single other machine along the way. And you shouldn’t.
You know the answer here, they are not to be trusted.
Samsung phones, for example, have a gpsd, which phones home at random times. This runs as root, ignores vpn settings (so no netguard for you!), and if it is just getting updated agps info, it sure seems to send a lot of data for that.
So no, they don't want a legitly auditable device. Too many questions, you see.
At the end of the day you need to trust Qualcomm or MediaTek. The Oracle of the hardware world, with more lawyers than engineers, or... MediaTek.
That's a NOPE for me.
If I’m not a terrorist/sex-trafficker/investigative-journalist, can I reasonably ignore those threats even if I, say, occasionally buy personal use quantities of illegal drugs or down/upload copyright material? (With, I guess, the caveat that I’d need to assume the dealer/torrent site at the other end of those connections isn’t under active surveillance…)
With iOS at least I know that apps really are sandboxed and cannot access anything unless I grant permission. No app can ever attempt to access my photos unless I explicitly pick a photo or grant partial/total access. Even then it's read-only or "write with confirmation, every time"
And you can deny the file access permission like any normal permission, most modern apps request music or videos and photos, rarley an app requests full file access.
Not that a Desktop with Windows would be any better. But I don't trust the OS itself, no matter how many layers of virtualization you put between code I choose to execute. The weak link is already provided by design. This isn't a technical criticism of Android, but the whole platform as being intransparent and paternalistic.
Not a fan of trusted computing because I doubt it will ever be used in the interest of users. It will be a requirement for some services, which I don't want to further support in their endeavours.
I talked to a security researcher specializing on Android at a conference and he didn't sound like he'd agree.
While I personally think ChromiumOS does a good job, I think a huge problem is that the issue is in how liberally complexity is added. And complexity is typically where security issues lurk. This has been seen again and again.
It's also why I think projects such as OpenBSD do such a great job. Their main focus seems to be reducing complexity (which they are sometimes are criticized for). A lot of the security seems to come from the reduced attack surface you get. And then the security mechanisms build, which typically are more easily implemented, because of said simplicity are the next layer.
And I think OpenBSD has reached a sweet spot there, where it's not some obscure research OS, but an OS that you can install on your server or desktop, run actual work loads, heck, even play Stardew Valley, or a shooter on, but have all the benefits in terms of security or simplicity that you can from research OSs, Plan 9, etc.
So maybe not mainstream, but mainstream enough to actually work with it. There's sadly many projects that completely ignore reality around them, also because their goal is to simply be research projects and nothing more. Then we have those papers that rarely everyone ever looks at on how in a perfect world all those big security topics could be solved. Unless some big company comes along and puts it into some milestone.
ChromiumOS seems like the limitations you get are similar, probably even more severe than what you get compared to OpenBSD's flexibility. That's something many de-google projects struggle with as well. At the same time the complexity remains a whole lot bigger. Of course goals and target groups are hugely different.
I think both Android and ChromiumOS used to put more emphasis on simplicity, but gave it up at some point. I am not sure why, but would assume that many decisions are simply company decisions. After all the eventual goal is economic growth.
That locking down on mobile devices is not just to increase security, but has the beneficial side effect of controlling the platform. This might not even be directly intended by the security focused developers, but it is a side effect.
So "most trustable" in that scenario comes with "most gate-keeping", "least ownership", etc., which we are kind of used to on smartphones, tablets and Chromebooks. So I think comparing it with other kinds of mainstream OSs isn't really leading to much.
But the nice parts of ChromeOS, as far as security properties go are the way it can be "power washed" between usages. Along with a desktop Linux system that has less binaries installed at it's base than most. And things that are built in are typically built atop chrome's sandbox.
I used to joke with my friends who ran TAILS Linux that my grandma with her Chromebook had the same threat model.
Who gives a shit about it enough to attack it a la (say) Windows?
The "Apple vs FBI" thing was a coordinated PR campaign following the Snowden leaks to salvage Apple's reputation.
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
Noob here, I recall often hearing that iOS has superior security to Android. Has this situation reversed in the last few years, or was it never true?
I suspect remarkably few people are qualified to objectively say which is more secure. If you're an expert on one, you're unlikely to be an expert on the other.
Security is multidimensional. It's unlikely there will be a platform that's more secure from every possible angle. What's secure for you might not be secure for a less technical person, or a world traveler.
In terms of privacy, Android is "compromised" by default, i.e. Google collects and stores a ton of private information about you. I believe Apple used to be much better, and still is, but getting worse.
Apple also does the same. Also, this only applies if you're running an Android device "out-of-the-box". Fortunately, there exist AOSP forks that mitigate this type of intrusion (e.g. GrapheneOS).
The pKVM hypervisor is new to Android 13 and requires Pixel 7 hardware, both of which are a few months old.
I would also assume the fact that their vertical integration all the way down to silicon is an advantage here as well.
Either the sandbox is very weak and Apple instead relies on App Store audits, or they disallow users installing apps outside the app store to protect their 30% tax that makes them a LOT of money.
As far as I can tell, there is no meaningful protection in place to prevent OEMs from poisoning the Android well (and the Android brand), even without considering the black box firmware running on wifi/BT/LTE/5G modems.
Cryptographic verification of the boot chain with Hardware root of trust are real. Heavily sandboxed userspace is real. Everything else would seem to be a reimplementation of common best practices (disk encryption), or a mitigation of a self-created problem (there shouldn't be binary driver blobs running on the main CPU to begin with).
And from what I remember, a plain AOSP install seemed to still phone home to Google to check for Internet connectivity and whatnot. It's awfully hard to put my faith in an operating system primarily developed by a surveillance company, as the working assumptions are a drastic departure from individualist computing. And trying to question those assumptions with independent devs is often dismissed (for a particularly striking example, see LineageOS/"Safetynet").
True, but those protections are enabled by default (on Pixels at least). Users don't have to do anything here.
> And from what I remember, a plain AOSP install seemed to still phone home to Google to check for Internet connectivity and whatnot.
You're not wrong, but GrapheneOS and CalyxOS are valid options, if you don't trust the ROM Pixel ships with. Even with a custom ROM you're left trusting the OEM. It'd be nice if we could have an open hardware / open firmware Android, but it hasn't happened, yet.
Users install apps and grant them full access all the time. Android phones are wide open no matter how secure the operating system itself is, because the security model for apps is so weak from a user experience point of view.
Aren't those still user-based? So, in the typical case of a single-user computer, a rogue app that I run with my account would be able to access my data.
There's the protected folders thing (not sure about the name) since a few versions ago, which attempts to block random apps from accessing random folders.
But it's opt-in (folders are not protected by default, you have to add them one by one). It's also all or nothing: either a given app is "untrusted" and it can't access any of the protected folders, or it's "trusted" and it can access all of them.
I can't say I trust Photoshop to only touch my pictures folder, but not my .ssh folder.
Asking because I base hardware purchases on whether LineageOS is available for the device and wondering whether I should restrict further to GrapheneOS or CalyxOS.
Knowing a PUK-code for a SIM card you own (and you can insert/hotswap) is all you need(ed) to unlock practically any Android phone until recently. Granted, this got reported and then fixed, it doesn't matter how good the TCB is if the front door is wide open.
I'd say that actual trust is hard to come by because you cannot trust what you see, since what you see is merely what is 'presented'. If a device says something like "the only Root CA I trust to sign my stage 1 boot loader is X", I still don't know if it is lying or not. I also can't do something like replace a SoC BROM since it's fused RO or simply a ROM (and not EPROM or Flash), or because the sources for that are owned by the SoC manufacturer, which isn't AOSP or Google, and I cannot inspect, build and run them. Hell, we can make this worse: even if I could flash it, who's to say that the memory I flashed is also the memory that is read when the SoC comes out of reset? What if there is a separate area on the die that has a different ROM that nobody told us about.
So trust isn't going to be purely based on "because this is the design we present you", but has to be based on non-technical factors and independent research. The former is mainly based on soft factors, and the latter is hard to come by and often just based on individual devices, not even an entire SKU release.
Architecturally, it seems to me that Apple with their own SoCs, bootrom, RTKit, iBoot etc. has a stronger platform trust case because they actually own the stack all the way with nobody else having a say about it. Especially with the spreading around of individually signed and verified hardware ROMs that don't even run on the same chips in the same device, a compromise would be very limited in scope. The only other hardware/software combination that would come close is the aforementioned Pixel devices since Google has almost all of the stack there as well.
On the x86 side it's a mess that will never be resolved, nearly every technology that was supposed to make it more trustworthy has been used to reduce trust and install persistent access outside the view of the OS. AGESA, IME, TXT, SGX, even the SMM implementations before any of those came along had problems that essentially circumvent any trust that was built up by other means. Even the hardcoded certificate signature hashes in the CPUs are coming in range if easy brute forcing (SHA1 mostly) which means that entire decades of systems can now think they are running trusted software from the reset vector all the way to the OS, just because a signature hash was using a crappy algo that was never intended to be used that way.
Windows is probably only ever going to be boot-trustable (but not OS-trustable) on ARM, just like macOS root-of-trust is pointless on anything before the T2 chip (and M1 later on). For Linux, it's about as trustworthy as you want to make it, but putting in the work is a PITA, so unless a distro or derivative (Qubes, ChromeOS etc.) does it for you, most users leave it as-is (untrusted).
> Architecturally, it seems to me that Apple with their own SoCs, bootrom, RTKit, iBoot etc. has a stronger platform trust case because they actually own the stack all the way with nobody else having a say about it.
That's why I specifically and only mention Pixel in my comment. Google's been doing their own hardware since Pixel 6. (iirc) Daniel Micay, creator of GrapheneOS, once said that Google shares firmware / proprietary code for the Pixel hardware "if you ask nicely enough".
Like you point out, eventually, one is left trusting a BigCo or worse assuming a flawed implementation is secure. Though, it isn't for the want of not trying. Or, to put it another way, "the best among the rest".
Sweet, so we can trust that our personal machine is only compromised by Google et al? XD
FWIW, I try to segregate my machines for different categories of behaviour - this laptop is for work, this one is for photos and personal documents, this one is for porn, this one is if I want to try something. But even still my trust in e. G. software vlan on my router and access controls on my NAS etc are limited in this day and age.
I feel today it's not about striving for zero risk (for 99.99 of people) , but picking the ratio of overhead and risk you're ok with. And backups. (bonus question - how to make backups safe in age of encrypting ransom ware).
It doesn't wake on LAN and there should be no way of knowing it exists outside of checking DHCP static addresses reservations - and now that I mention it, maybe I should remove it from there too.
This minimises the size of the window, and network-snoopable information, required to compromise this set of backups.
This is actually a solved problem, with many solutions. In a nutshell, you need a system that has enough space to make many enough copies without overwriting the ones that are too fresh. It also must not be controllable by the host that you backup but this is kind of obvious.
It doesn't matter how many files your computer has and how many millions of lines of code it runs. There is a concept of Trusted Computing Base (TCB), which is the part of the code that you have to trust.
In Qubes OS it's only about a hundred thousand lines, and doesn't include any browser. The key is security through isolation.
You run your browser and network in virtual machines and assume that they are compromised. You keep your sensitive files in an offline VM.
Versioned, offsite backups. For instance, if you have a database in an AWS account:
* Give the backup process write only (I.e. no delete permissions) to a GCP account.
* Create the backup in AWS and timestamp it
* Copy the backup to GCP using the above permissions.
* If you want to be more secure, copy the backup to a USBHDD (daily/weekly) and unplug it.
I've looked into this before, and it is just not that easy. "Write" is delete, for most cloud storage systems, for the practical purposes of trying to keep a backup safe. (I.e., you might not be able to delete a blob in some bucket, but if you can write to it, you can just overwrite it with 0s.)
"WORM" (write-once read-many) tends to be the term to search / gets the right documentation from most providers. In GCP's case, it appears to be "set up a retention policy", and that's similar to my experience with other providers. These bring their own set of problems.
That said, encrypting ransomware isn't going to magically determine where your backups are, and for most orgs, having the backup at all (and having it tested) is the priority, not the whole WORM thing.
(Orgs, IMO, also tend to get really uppity about having "database" backups, where "database" == {MySQL, Postgres, etc.}. But then there will be an S3 bucket that also has a bunch of data in it, and that never gets backed up, and nobody even questions that. And half the time it seems impractical to back up, too, due to a mix of cost and S3's design.)
My even shorter (and incomplete) summary of the document would be: configure your router and firewall; remove default passwords and crapware from your devices; use a lock screen; don't run as root; use a password manager and decent passwords; enable 2FA everywhere you can; enable anti-malware if your OS has it built it; don't run software from untrusted sources; patch regularly.
There are also other controls that you can choose to impose on yourself. For example, I require full-disk encryption, and I will only use mobile devices which get regular updates. Would be interested in hearing other things that HN'ers do to limit risk.
Given the most common network activity is web browsing, it seems like enabling protections in the browser is becoming mandatory for the security-conscious.
For me this amounts to enabling NoScript and uBlock[edit: [0]] plugins in Firefox, desktop and mobile versions, and disabling or locking down various "features".
An additional step I take is to use several browser profiles for different purposes (mail, banking, shopping, default, to name four) so that Firefox always asks me to pick a profile on startup. As well as reducing the possibility of XSS, this lets me relax the settings for some profiles where I restrict myself to a small number of trusted sites. (This may well be overkill!)
0: uBlock Origin, that is, as per instructive commment below[1]
I also made an app and extensions to help me use multiple browsers, one per site. (Browsr Router)
What I am looking for is an easy way to run something like a LiveCD OS in a VM for browsing. The problem is that I have never found a decent LiveCD that has Firefox with all of the mandatory extensions (uBlock Origin, etc...). I guess I could customize my own LiveCD, but last I looked into it, doing so seemed complex and too time consuming to figure out.
Posting this in the hopes of being steered towards a simple solution or to inspire someone to create one.
Mostly the same basics as you. The document you linked is a good starting point.
I'd add extensive use of virtualisation and sandboxing. I run less and less software as native, installed applications on any device I use personally or professionally. Instead it tends to run inside things like VMs or Docker containers or cloud-hosted platforms now.
My basic policy is to try and make every device and installed application expendable/replaceable in case anything breaks or gets compromised and then focus on the data. I apply the principle of least privilege for access to any sensitive data, try to keep all important data in standardised formats and avoid lock-in effects as much as reasonably possible, and keep good back-ups under my own control with the ability to redeploy/restore anything quickly and as automatically as possible.
I generally use a device as an access mechanism; a configured window into the data. This configuration is the only thing lost when a device is lost. No data, no function, no service. Configure the replacement device and continue as you were.
Virtualisation and Docker-isation makes backups and restores almost enjoyable.
Since Ubiquity started fown the cloud-first path I’ve switched to Mikrotik. While they do seem to have regular CVEs (which is good, I think?), they also don’t seem to have a public bug bounty program.
I was thinking about getting a Ubiquity router because it has good support for setting up wired VLANs without needing to go down the path of finding a solid OpenWrt router.
Is it really true that you can't access the router's dashboard and configure things without associating an online account to your router?
* Windows
* storing data on other people's computers (cloud apps)
(Yes, they're all safe under the right circumstances. But the right circumstances are far from universal.)
And loosing access to important stuff can be worse than other people seeing the stuff - anything behind a google (etc) account can be lost in a moment, due their mechanised decision making and inability to meaningfully contact humans.
If you can't always easily contact a helpful and authorised human, the continuing existence of your stuff is a gamble. And no, setting off a twitter storm and hoping that the company will be embarrassed into restoring your data is not a suitable contact method!
And do you always check for keylogger thumbdrives and such?
This was a corporate requirement where I used to work, unofficially reinforced by the local jokers who would rotate the screen and / or send prank messages if you didn't.
Same here. The all time favorite is sending a resignation notice to the person's manager (the manager usually gets a fair warning first and plays along with it).
My colleagues edited my .bashrc to echo "lock your screen next time"
Check for keylogger thumbdrives: I use a laptop so it would be immediately obvious. But now that you say it I haven't checked the charger USB-outlet on the back of my cabled keyboard.
[1]: it has happened I have failed. Once a year or something.
[2]: I sometimes try to allow myself to go downstairs in my own house to fetch a cup coffe without locking when I am alone, but I find it so stressful in practice I always lock it. I don't need to know but it is a good habit. I'm otherwise normal :-)
On Windows, Win-L to lock.
When home, I always have to lock or my cat would typeeeeeeeeawww
I haven't used a use usb stick in +10 years.
We have a pretty standard setup at work: screen times out after 15 minutes, and co-workers teach you pretty fast to lock your machine.
At home, where I use a MacBook Air, I work in a physically unstable situation...in a rocking chair, on my lap. Whenever I stand up, I close the machine, which locks it immediately. If not, I risk the machine sliding to the floor.
For the rest, I run a pretty esoteric setup (compiled-from-source custom configured linux kernel with no binary blobs; all software compiled from source, with no exceptions; aggressive, burdonsome-to-me privilege separation; chroots and VMs for various degrees of potential threat; etc). I have no illusions that it is perfectly safe. What I am comfortable with is that, in order to compromise me, you would have to know a lot about what I run and how I run it. I believe that I would have to be nearly individually targeted to extract any useful data from my machine, and that I am not nearly a valuable enough target for anyone to do so. I think you would have to be a state-level actor or someone with similar capabilities to compromise me, and none of them would care enough.
My security paranoia stems from extremely sensitive work I did as a lawyer long ago, but I am now so used to it that I carry on as a scientist, even though my current work is not nearly so sensitive (if at all). I give up a lot of convenience and some functionality to operate this way, so it is not for everyone. I am not an adversary to anyone, so outside state actors surely don't care about me. And my own government can just get a warrant and knock on my door, so they don't care about me either.
Embedded device firmware besides the bios is probably my main vulnerability, but if you're successfully getting at me through my hard drives or mouse, then I was surely an incidental rather than actual target.
To answer your questions, oh hell no; definitely I do not audit source code myself. Though I have rarely. I do it this way, and it is different enough for me, because someone could audit the source in theory. If someone did audit and found a security problem, then I could check to see if my source was also compromised. If I install binaries, then I might not ever be able to know if my binary was compromised. Maybe someday if reproducible builds are guaranteed to be bit-perfect, then I would use binaries from reputable sources, but that would only happen in the case where third parties are compiling from source and affirming the reproduction. In that case, why not just compile it myself?
Developers who publish compromised source are going to get burned. Developers who publish compromised binaries are going to say, "omg we must have been compromised by someone else." Obviously it is possible for third-parties to compromise source, but I'll go with what I see as the lesser threat.
If the cost of compiling was high, then that might make a difference. For me, the cost is negligible, which makes it a no-brainer for me.
Are there guides you found helpful?
For adversaries below the level of the US intelligence agencies, I run everything virtualized and compartmentalized with Qubes, the installation image for which I verified the dev-provided cryptographic signature matches. I try to rigorously avoid any software operated by Google, Amazon, Microsoft, Apple, Facebook, disable all JS by default in my LibreWolf browser, refuse to connect directly websites protected by cloudflare, audit source code for almost everything I run in userland, etc etc etc.
This is all for my personal machine. For work devices, I assume they're pwned even worse and I do nothing but actual work on them.
On the mobile side, GrapheneOS on a Pixel for my first phone, and a linux phone with hardware killswitches for bt/wifi, cam/mic, and baseband for my second phone.
All of this in addition to solid fundamentals like network traffic monitoring, very restrictive firewall, offline encrypted hardware password manager with no password reuse, etc.
What do you do in case you want to use a website protected by cloudflare?
For strictly reading public webpages, public paywall bypass tools and archive sites work pretty well.
https://puri.sm/products/librem-5/
They also have a "made in USA" version (though the case is made in China and the wifi chip is made in India). It's even more expensive, and I certainly don't trust that USG/IC hasn't attempted to backdoor this either - we know a lot of ARM processors have the TrustZone, which is very similar to ME/PSP (I believe an ARM TrustZone core is actually how PSP is implemented), but the lead time is much shorter.
https://shop.puri.sm/shop/librem-5-usa/
Note that I'm not formally endorsing them, just sharing what I use.
If you’re worried about the impact to your broader organization (which is what most of the sophisticated threats tend to target), you should think about risk mitigation through the Swiss Cheese defense model. Each system is inevitably going to have holes, but layering them on top of one another will incrementally improve your coverage.
For instance:
- Your team should be trained about phishing attacks. But inevitably some will get through, so…
- You should implement 2FA in case a password is compromised. But a threat actor may be able to capture a 2FA-passed SSO session token, so…
- Production access should be limited to a small number of individuals. But even they might get compromised, so…
- You should programmatically rotate credentials to make old leaked credentials useless. But a newer one might be captured, so…
- Data should be sufficiently encrypted at rest and in transit, and…
- Your team should have an incident management system and culture in place to quickly respond to customer reported incidents and escalate it to the right level and…
- Audit logs should be tracked to understand the blast radius in case of compromise - and so forth
When you look at incidents like CircleCI and LastPass, a good security organization will understand that there was more than just one point of failure and should talk in detail about how they are shoring up each level.
Personally, I assume the hardware is already compromised and plan for recovery accordingly, starting with the worse case scenario. Then, I ask myself "If this thing isn't compromised yet, how can I help it stay so?", starting probably with the network access, through firmware, all the way to the browser.
At some point you just have to admit there's limits to privacy and work with them. You paper journal could be stolen and read / rewritten too, yaknow? It's not a new problem, its just in a new context.
I try to limit attack surface in the following ways:
- I only use M1 Macs as desktops. This reduces attack service in various ways. M1 Macs do not have anything like UEFI firmware, it all starts from the iBoot ROM and the whole chain is verified with signatures. The OS is on a sealed system Volume that is read-only and signed. Altogether, this limit firmware/OS attacks.
- I use a U2F key and/or the Secure Enclave of the Mac for credentials (SSH keys, 2FA). They are set up to require user confirmation.
- When possible, I will install applications from the Mac App Store, since they are sandboxed by default.
- I use separate work and private Macs.
- I clean and factory restore my Macs every few months.
- I use some tools like Knock Knock to see if there is anything suspicious.
Compromise is obviously possible, but I try to push it into 'mostly state actor' territory, because I am not interesting to most state actors.
https://www.qubes-os.org/intro/
For details on how I use Qubes specifically see: https://github.com/hashbang/book/blob/master/content/docs/se...
How is this not a contradiction?
>6. Manual PRIVILEGED SYSTEM mutations MUST be approved, witnessed, and recorded
>7. PRIVILEGED SYSTEM mutatations MUST be automated and repeatable via code
* Software: Canonical, Google, Microsoft, Valve, Oracle, Dropbox. I install software from their official repos and keep it up to date. Anything 3rd-party/unofficial/experimental/GitHub goes in a VM.
* Hardware: I built my main PC from mainstream commodity components. I have no way of knowing if there are secret backdoors but I consider it unlikely.
I use a password manager, I enable 2FA, I turn off things I don't use, and generally have a low-risk hygienic approach to computing.
I’m also privileged enough to not be a “person of interest” so don’t feel the need to take any extraordinary precautions.
Yes, I’m aware of VM escapes. Yes, I’ve read Reflections on Trusting Trust. I choose to trust regardless because life’s too short for paranoia. As Frank Drebin said:
“You take a chance getting up in the morning, crossing the street, or sticking your face in a fan.”
https://www.techrepublic.com/article/is-the-intel-management...
There is hardware that doesn't contain those at least, but it doesn't break power records.
(This is not an argument for mass surveillance, it's just a practical assessment of the risk).
* Software: Google, Microsoft"
I trust that Google and Microsoft won't hack into my bank account and steal money, even though they could, but otherwise I assume they collect anything they want and can.
So now I disable automatic sample submission via group policy but Microsoft definitely can and will access files that they really have no business accessing.
Fun story but my laptop was actually hacked remotely once, without me knowing.
It was almost 20 years ago, some would call me a script kiddie. Just trying to be bad ass, trying to live the movie Hackers. Had a stolen laptop running FreeBSD, with a wicked bootsplash just like the kids in the movie.
So you can imagine I was moving with the wrong crowds online, having little defacing wars with other groups and shit like that. Caught the wrong kind of attention.
I say that infosec comes naturally to me now but pobody's nerfect and back then I had re-used a password in a weakly encrypted service database, someone hacked this service, found my password, found my ssh logins to the servers, and traced backwards to my laptop.
I don't remember the details but somehow working back from one server, perhaps to another jumpserver, they were able to get the IP for my laptop and actually login to it.
Fortunately for me they didn't do anything but gather data, they posted this on a wall of shame saying "another hacker down". I say fortunately for me because I had thousands of customer's data on that laptop, including CC#'s for the business I was running at the time. They missed all this, and the very next day I reinstalled my laptop and reset all passwords on pure coincidence. I had no idea I had been hacked, I just felt like reinstalling for some other reason.
Found their wall of shame posting later and felt very much ashamed.
This thread has inspired me to setup a tripwire for my workstation. It's something I used to use many years ago but I think it's a good setup to have some sort of alerting if files start changing.
So you really have to boot from trusted media with a trusted kernel and no untrusted modules to be sure what you are seeing. Generally this involves rebooting onto trusted readonly media, doing a scan, then rebooting back into production. The HOWTO mentioned finding an unused kernel module like floppy.ko and replacing it with a malicious payload and ensuring it loaded on boot.
Also keep in mind that attackers are well aware of tripwire and some attack kits I saw specifically looked for tripwire like approaches and would hook into the update the checksums process after patching so their exploited binaries would look just like valid binaries.
Can you explain what you setup?
But then I got to thinking, if I'm going to do a clean Fedora install for the tripwire (it's best practice) I might as well try Fedora Silverblue[2]. Silverblue is an immutable system so it kinda makes a tripwire less useful because no one can change any system files. Only files in your home directory and /etc can be modified statefully.
From there, take appropriate actions. For the vast, vast majority of us, that means using good passwords, updating software, and not running weird things from the internet.
If you’re worried about 0 click RCE in Chrome/Windows/iOS, you either should be getting better advice from folks outside of HN, or are being unrealistic about who is coming after you.
This is my computer, let me tell it what to do. I hate how much of my time is wasted by all this security stuff. Infinitely more so than had been wasted by actual malware over the last decade or so.
I don't want to have to spend 10hrs figuring out how to hide root from Android pay every time something upgrades. Please just let me have root on devices I own.
Ever since I started doing a lot of work in C where all the foot guns are intentionally left in I've had my eyes opened to how beautiful and fun computers can be when they aren't your fucking adversary.
"Security" that can't be disabled by the device owner is tyranny.
I’m a security engineer and know what I’m doing and agree there’s some level of security theatre, but it you’re not worried about losing Crown Jewels from a compromise you’re most probably uneducated or arrogant.
It is about their bottom line, but largely not to protect me or grandma, it's about justifying control and divorcing people from the power of the supercomputer in their pocket. There's more money in making it hard for me to edit my hosts file etc. than there is in preventing the potential loss of my money/data through these restrictions.
If you are a standard person and not doing any illegal, the information that you need to protect are mostly related to financial and personal standpoint. So you need to protect you bank/credit card/cryptowallet with encryption and/or MFA. For financial information, use the same criteria, according also to level of continentality that you want to achieve: it's stupid to encrypt your cat pictures, it may be worth to encrypt cipher your son pictures, it's mandatory to protect your health related files also with MFA. This is just to have an idea, you should make this exercise frequently (let's say every 6 months) and verify if the security controls are in place and have to be updated.
For my own devices, I am using this approach:
* Infrastructure: I am using a password manager with MFA for all my accounts and where is possible I have enabled MFA. I have Cloudflare ZT on my home network, so I am a bit protected against web threat. Moreover, I have a script that everyday download phishing and malicious feeds and update my router's ACLs. I am not exposing anything on public, all the services inside my house are accessible through VPN. My Chinese camera are heavy firewalled in a different VLAN and reachable only from specific host. Every device is upgraded to last version and no default passwords.
* Main laptop: is running Linux, so I am feeling a bit more safer during the web surfing. Anyway, I have an encrypted backup for important data over cloud, just to be ensure disaster recovery.
* Secondary laptop: is running Windows, I am keeping it regularly updated with scheduled MS Defender scans. My wife is mainly using it, but she is not installing anything without my approval (I am the admin of the laptop).
* Phone: Storage encrypted, access protected by strong PIN and no biometric. Applications are installed only from official stores and using a DNS blacklist. My phone has a native feature to reduce and auditing app permissions on a schedule and I am doing it by myself as well sometimes. In case I have to connect to an unencrypted public network, I am using a Wireguard VPN client.
Just my 2 cents, I hope to did not forget anything and be helpful.
All: patch, encrypt, backup, track power, isolate workflow by device/VM
Network: router with OSS firmware, workflow segmentation, reduce wireless
iOS: (>A12 SoC) Lockdown mode, Brave w/o JS, daily reboot
iOS: periodic reinstall from DFU mode, Apple Configurator / MDM policy
macOS: hardening script based on workflow, outbound firewall
Windows: Secured Core device + SystemGuard + App Guard VM isolation
Windows: HP device + SureStart (f/w check) + SureClick (browser VMs)
Linux: vPro device + QubesOS with Anti-Evil-Maid
Linux: generic device + non-persistent LiveCD OS imagehttps://www.infotechnotes.com/2021/07/microsoft-windows-core...
I don't believe there is a way to be 100% certain, but if I had to go to a store and pick a new device with the lowest likelihood of being compromised, it would be a desktop, a laptop, or a tablet running ChromeOS[1].
[1] https://www.chromium.org/chromium-os/chromiumos-design-docs/...
From the security perspective, it's much better, because every single app is running in a sandbox.
I don't even use Chrome for web browsing on ChromeOS, since Firefox works just fine with flatpak[1].
[1] https://support.google.com/chromebook/answer/9145439?hl=en
Of course if you have large quantities of BTC or something then the answer is to get it off of your personal machine and setup a cold wallet that cannot be hacked, and stop installing clever looking crypto shit on your machine.
You can get one for not less than $5,500. https://www.raptorcs.com/content/TLSDS3/intro.html
The pivotal word in this question is "you". If you allow a third party, e.g., Google, Apple, Microsoft, a "Certificate Authority", etc., to decide "trust" on your behalf, then it is the third party that controls "trust", not "you".
A third party can tell "you" that "your personal machine" has or has not been "compromised". The third party can decide who to trust.
However, this is quite different than you deciding who to trust.
Under the trust models promoted by "tech" companies like the ones mentioned above, ultimately "you" are not supposed to be the one deciding trust. They want to do this for you.
Unfortunately, "tech" companies are themselves third parties and they may have commercial interests counter to yours.
- clean reinstall every month, just pick a new flavor of Linux to try out. (also helps ensure I have proper backups and scripts for setting up environment)
- Dev work I usually do in docker containers, easy to set up/nuke environments.
- Open source router with open source bios (apu2), firewall on it, usually reinstall once in a while.
- Spin up VMs via scripts for anything else. (games - windows VM with passthrough GPU for example)
- automatic updates everywhere.
this is not sustainable. you do this once and then pray nothing breaks!
If something breaks or I get bored, nuke the active one and start clone, update it and make another backup, then reinstall games again.
On the other hand, gpu pass-through breaks once in a while and is annoying to fix.
[1] PDF: https://www.andrew.cmu.edu/user/bparno/papers/bootstrapping-...
I think its completely impossible to make sure your machine is not compromised. You can just take the best effort to keep it clean.
Try to use 2FA as much as possible. And try to shield the 2nd factor as good as possible from any connection to your other devices.
What really bugs me, that some systems rely only on the 2nd factor, which replaces the password completely. Some even did that with SMS. So you put in you user name and then the SMS code. That’s really bad. Also a lot of Services disguise this method in the „I forgot my password“ function, where you can reset the password just with a sms code.
I was looking into things like GitHub Codespaces, I believe they're isolated per repository and integrated into VS Code, but I'd like something I could run on my machine or a server of mine.
And don't give any software root access.
All I can do is to start with a machine I believe to be "clean", and take measures to keep it that way (others have suggested suitable measures). But even a brand-new machine might have a compromised BIOS, or compromised firmware in some peripheral processor like the Wifi adaptor.
I don't know how to guarantee that a machine is "clean" to begin with, and I doubt anyone else does.
Like with driving, make an effort to lower the probability to wherever makes you comfortable, then just accept that there's a non-zero chance it wasn't good enough.
I understand that my "personal machine" - my body - is always compromised. I also have faith that no heinous actors are likely to try to compromise my body. But that is only because I am a nobody and have the good fortune to live in a safe place.
As for computers, I think the same logic applies. I have faith that no nefarious actors are striving to compromise my own machine specifically. But for many high-value targets, this would be a bad assumption. Witness the crypto thefts that have occurred by hacking individual's computers.
I am no expert in counter ciber espionage, but my understanding is that it boils down to a) reducing attach surface, b) using trusted hardware, and c) using ephemeral "machines".
The only option we are left with is to operate under the assumption that, indeed, our machines are permanently compromised.
I #BuildInPublic as much as possible on GitHub and GitLab and dedicate everything to public domain (http://pledge.pub/).
I have a number of computers and can be up and running on a new Macbook in under an hour.
I run multiple mirrored web sites.
I distribute crypto keys across ledgers and safety deposit boxes in multiple states.
Most importantly: I don't pay for insurance (except for mandated auto and homeowners). Instead, everyday I go out there and try to deliver as much good to as many people as possible, knowing that the best insurance when bad luck strikes isn't some check from some corporation, but the helping hands from your fellow neighbors.
security(7) man pages on FreeBSD and DragonFly, I think originally written by Matt Dillon also tells you to assume breach for example for the root password, which is why you shouldn't allow password based logins over SSH, etc.
This is the earliest I could find, and it already contains assuming breach in 1998.
https://github.com/freebsd/freebsd-src/commit/f063d76ae36ca4...
Does anyone have an idea on how to see the file and its history from where it was moved? I checked 4.4 BSD, because the copyright mentions Berkley, bit I failed to find anything in the man1 directory.
For the rest, the thing is so complicated nowadays I can't really say anymore.
I spent my youth on 8 bit machines. At that time I was 100% certain there was no compromise. But nowadays,...
Android, on the other hand... I have installed apps I didn't know much about, and that store is full of malware, so I have no idea.
It is most likely compromised and I behave accordingly.
So I feel fairly confident about the machine firmware & OS. Less so about my keyboard for example. Also because i opt out of a lot of the securities (e.g. i download from homebrew rather than using app store apps), I can’t be sure i’m not being compromised.
Only half kidding, unfortunately.
So either my personal machine is not compromised, or they think the amount of crypto in the wallets is too low.
Jokes on them though, cause I am moving my crypto to a hardware wallet eventually
If the U.S. has backdoors on every PC, they're not going to bother draining the wallets of "small fish"; they need to keep these things secret so they can go after terrorists
I think this guy had gotten my phone number from my HN profile and he thought I might be able to help him. He thought his android phone was infected by malware and he knew who did it. I told him the people who repair cell phones at the mall could do a system reset on his phone…. Unless he was dealing with state-level actors in which case it might be an advanced persistent threat and it might be permanent.
And since the video card is old and internet is spotty, brother Bitcoin miner and ransomware delivery man won't have much to win either.
The rest of automated attacks have to go through basic PC os protection (firewall, antivirus, hardware locks for unwanted code execution, etc).
It's the digital equivalent of "in god we trust"
On a similar note services and networks should be treated as compromised as well, meaning you must use encryption, authentication and in general make sure to limit attack surface.
And all of that boils down that you should make sure you should not rely on services, users, etc. don't for example access personal information they are not supposed to access.
After all the problem with things like Ransomware is exactly that this isn't assumed.
And I don’t just have to be vigilant about what I do, but also about what my team has done. It terrifies me, and it’s a sad reality that my personal risk is reduced by the fact that if I fall victim, countless other teams will as well.
Not always, but often I prefer development on remote VPS’s. For anything deep learning I pay Google a little bit of money every month for Colab notebooks, save a ton of my own time, and don’t worry about trying random 3rd party libraries. I don’t have this use case anymore, but I used to use very large memory VPS’s with SBCL Common Lisp and Emacs to work on an old project that required lot’s of data in memory - VPS’s are really cheap if you turn them off when not in use.
In the 1980s and a bit into the 1990s, I did most things in X Windows - I have thought about how good that would be for secure remote development, but text with tmux, Emacs, etc. is so much less hassle.
Second, unless you're in a situation where you've pissed off/threatened some rather large actors, you should be fine assuming you follow best practices for backup, software, update and password management and you avoid using things like cheap IoT devices to connect to your cloud services.
Third, when disaster strikes, keep calm, rely on backups, change affected passwords and notify others who might get affected.
I consider internet browsers to be a be a major backdoor risk and thus have none installed on my host OS. I only browse interwebs from VMs.
I don't trust my home network the same as I wouldn't trust an open public WiFi.
I don't assume everything is as secure as it could be and am taking redundant steps to ensure certain stuff.
Eben Moglen: The alternate net we need, and how we can build it ourselves:
I do trust iOS and iPadOS in Lockdown Mode, and I avoid installing apps, usually preferring web apps.
I have a Chromebook and I also trust that.
In all cases, I don’t wait to install available system updates - that might not be the best strategy, but that is how I do it.
* Using Yubikey PAM always as a 2FA for ssh,sudo (also on every Linux in my home network).
* Always require authentication on each sudo command (prevents escalating once and then reusing privileges).
* Only running Docker with sudo as recommended (requires 2FA now).
* Closing all traffic other than services I need with nftables.
Regularly look at the journalctl for suspicious activity.
Perhaps somebody can confirm if it's a good idea or not, but I like to generate only 1 emergency code for Authenticator (the least) and then delete that line in ~/.google-authenticator. Also, permissions of 400.
In case interested, check it out in code here: https://github.com/mihaigalos/config/blob/main/services/pam/...
When I first got my laptop, I installed a fresh copy of Windows 10, installed all my commonly used applications, configured all my settings, and then enabled UWF. On every reboot, it goes back to this clean snapshot, no matter what I do - And reboots are quick too (~10 seconds).
I'm never worried about making changes to my laptop to try them out (installing a new program, configuring obscure settings, etc). If I don't like it, I can get back to my clean state with a simple reboot.
Still vulnerable to BIOS-level malware though, I suppose.
(Note: I repeated most of this from a previous hackernews comment of mine)
Once Advanced Data Protection switches on globally "in early 2023" I'll have another compartment. But I assume that someone can access basically everything. You can have fun with it.
I also think what's happening on my devices is some of the least interesting parts of life, so, yeah, there's that, too. :)
I'm much more wary of systemic malware at lower levels that I don't have an opportunity to detect. There's not so much I can do about that other than try to use devices from vendors I trust (or distrust less) that have the least preinstalled software. Lobbying for open firmware or hardware is the long-term strategy.
I also use multiple machines: work, personal, gaming, and utility (Surface Go). E.g. I use the mouse configuration software on the Surface Go and only the mouse hardware with its configured profile on the other machines.
Ultimately I can't know I'm not compromised but don't lose sleep over something I don't have more control over.
As far as I know I did everything right, and someone called my bank with info we both believe they got from stealing from my paper mail and got access because they convinced some human at a bank's call center they were me.
Don't make it easy for people (rng passwords + password manager, 2fa, don't run as su, whole disk encryption, don't leave you computer unlocked, don't log into your bank on rando computers you don't control, don't use untrusted wifi). However, assume you already are compromised and will have to deal with it some day.
Once you think that way, you don't need to stress that much about getting the perfect hardware solution or being super paranoid - buy a device you like, and enjoy you digital life. Stuff happens sometimes and if it does you can deal with it ¯\_(ツ)_/¯.
I distro hop chronically on most of my machines. Sometimes multiple OS reinstalls across machines per week. Some installs have lasted a few months but it's rare.
I try to stick to official repos when I do reinstall, so I'm outsourcing that trust to the distro maintainers.
If it's on the disk, it's gone except for a few important files I keep in a self-hosted Nextcloud sync folder.
I use LUKS encryption to ensure leaving the laptop on the bus is a non-event. If it was ever in somebody's possession for very long (border, police, lost and found) I'd just put it in the garage and never touch it again.
Firmware malware is pretty uncommon, still, so I'm just hoping for the best there.
check that it's still there from time to time; any automated malware will slurp it up
Going from that assumption, I take care to keep encrypted backups of all of my important files both locally on another machine and remotely.
I also use two-factor authentication wherever possible, because I find it unlikely that the same attacker would gain access to both my PC and phone.
Additionally, I have a second phone with no SIM card that I use for some TOTP 2 factor accounts that I wish to remain especially secure.
Operating at the assumption that you have already been compromised allows you to prepare for the worst should you truly be.
So I trust that regular caution and OS security reduces the risk to an acceptable level but mostly I don’t fear anyone reading or destroying my data because I have backups and it’s not sensitive. Sure it would be scary from an integrity perspective, but not in any other sense. Even constant access to my machine and everything I do wouldn’t be a big risk.
So if I’m affected by a ransom Trojan (most likely scenario), I’m happy to just wipe my machine.
This is also why using an open source OS is so important. At least you can investigate why something is happening in the OS. Without the source you can only guess at what is happening.
BTW, it is not that hard either. You can even have multiple Linux kernels installed at the same time. Same with Android ROMs, just checkout the code, build it and flash using ADB. It is about as difficult as dual booting Windows and Ubuntu.
[1]: https://wiki.archlinux.org/title/security
[2]: https://wiki.archlinux.org/title/List_of_applications/Securi...
I feel that our OSes should solve this problem. Unix was built with the mindset that other users cannot be trusted, but they forgot that applications can also be malicious. There is a huge opportunity here for better OSes.
In short: 1) secure bootup by locking up BIOS and encrypting your drive 2) set User Access Controls to the highest level 3) install up to date browser with appropriate addons (ublock)
Up to a week might be prudent to avoid patches which blow up, but not longer.
I assume a freshly installed OS is compromised [1] and the hardware it is on is also compromised in the BIOS and firmware at very least by state actors but then I also assume those state actors have poorly vetted contractors that may also be compromised by other nations i.e. who pays the most gets access. I would not be surprised for a moment if they have competing backdoors that try to block one another. Since I can not control any of this I just imagine the national actors of the world are watching my screen and yawning. More likely the latest iteration of ECHELON AI is yawning. I instead focus on securing important externalities making bank accounts read-only from the web, not all banks will do this. I also diversify where my assets are stored and make a best effort to require physical access.
Beyond that layer I do all the usual hardening practices but that only goes so far as every browser likely also has intentional weaknesses in them. Even FireJail and SELinux/AppArmor will likely just happily relay malicious instructions. Addons may raise the bar keeping some script-kiddies off my machine but I never for a moment assume that it stops government contractors from relaying instructions to the backdoors in the hardware and/or OS and ultimately to the hidden CPU instructions that likely take multiple layers of obfuscated instructions to tickle meaning SandSifter will never find them.
The above is for PC's. For cell phones I assume FAANG are interactively on my phone and since most of them were initially funded by the government. I do not use it for anything sensitive. I also assume that all cell phones have backdoors added by their manufacturer. Each one does seem to dial home to different places and make unique DNS requests. Putting phones into developer/debug mode does seem to quiet them down which is the opposite than I would have expected so maybe they know someone may be watching. i.e. malware knows it's in a sandbox
Wi-Fi Access Points are a story in and of themselves.
Why should I care about state actors? That one's easy. The best contractors will have leaks in their OpsSec and for-profit companies will acquire the weaknesses and use them to do illegal and unethical things to citizens for a price and political, economic and a myriad of other motivations. I would not be surprised if some government actors sell off access and end up working for said companies.
[1] - https://news.ycombinator.com/item?id=34388990 [and hundreds of other threads]
Well, presumably it would stop yawning if you were, like, part of an armed rebellion. The perspective I'd like to hear would be the Ukranian civil and military resistance to Russia's invasion. How do they know their systems aren't compromised? Because, yeah, in their case, being compromised means getting killed.
In fact there have recently been articles about this and each side ordering their troops to stop using their cell phones. Both sides have attributed several mass casualties to cell phones. This is probably harder to enforce with conscripts and military contractors. Many of the first wave of troops thought they were just going on a training exercise.
The question is: is there some reason to trust, and the answer is: no.
In my opinion, any and all general computing devices sold to the mass consumer market are already compromised in some shape or form as they roll out from the factories -- otherwise such things would simply not be sold in large quantities.
You don't. They are all likely "compromised" to some extent. The vast majority likely have asymptomatic/latent state-sponsored vulnerabilities, if not on the machine itself, then in the network infrastructure it uses. For the most part, people might not consider them "malicious third parties".
Generally, it’s a bad idea to believe things without evidence, so I guess you can trust your computer isn’t compromised the same way you can trust no unicorns exist; there’s not any credible evidence to suggest it.
But random malicious code in user space? Well, I really just hope for the best :)
OS/app level: occasional AV scans, though I don't trust clamav as much as I trust Windows antivirus.
I should really properly set up secure boot on my desktop to make rootkits harder to install, but Linux and secure boot are just too much of a kludge.
"how can you confirm that your machine is not compromised" => "how can you check if your machine is already compromised?"
For the former, I don’t assume anything especially since I’m not an American citizen. I still believe with some certainty that my iPhone is safe from the government but not 100%
Until the day we get sandboxing, well-defined interfacing with user data and stuff in desktop computing...
Imagine the desktop's security model, if you can call it that, on mobile. It would be madness.
Thats also why 2fa is the first thing i configure after setting up a kubernetes cluster too.
If I see any anomalies, then that's a hint.
Note, you should not fully rely on this but rather as a starting point.
That is... I don't trust my machine.
I take reasonable precautions, but at a certain point you have to just live your life and deal with people who violate your boundaries in meatspace.
"The three golden rules to ensure computer security are: do not own a computer; do not power it on; and do not use it."
Generally I don't install random software outside the official repos or AUR, but I do blindly trust those repos to not be compromised.
That being said, I don't think I could 100% trust a modern computing device to not be compromised, but since that isn't possible I also don't see it as actionable information.
"There is no way to really know if a computer is compromised" - Joanna Rutkowska
Any ways in which AI can already help?
Dont install weird exe or MSIs
Thats kinda it.
why do you even care? most of your files are either on apple's computers or google's computers
Best advice I have, for what it's worth is to wipe and reformat from a known clean image regularly. If you haven't been hacked yet, stands to reason you wont be hacked going forward.
That said, I often install packages I don't fully vet, and grant permissions I probably shouldn't, either in the name of curiosity (how else do we learn and experiment), or necessity.
I use Linux with lots of distributed sync and backups with e.g. Syncthing (plus copies of stuff NOT on sync thing)
Now, I'm aware many reading this are going to nerd out hard (like how the top comment now is "Android/Chromium" which I'm skeptical of but haven't done much homework on? Maybe?)
But because you said "personal machine"-- I'm thinking about my own threat model and my years of experience.
Thus, not going to much worry about, say, some obscure Linux-Stuxnet-thing, which not only is overwhelmingly unlikely, but also something I can't much do anything about beyond the solutions I mentioned above.
More likely, I can avoid stupid Windows and stupid Mac,and often stupid Web mess by what I'm doing now.