HNHacker News
TopNewBestAskShowJobs

akyuu

7,275 karma · joined October 14, 2018

submissionscomments
akyuu··on Show HN: Sheriff: Block JavaScript and Cookies per Domain, in Safari
From https://primatology.xyz/sheriff/faqs:

> Does Sheriff block all JavaScript?

> No. Sheriff only blocks externally-loaded JavaScript. That is, JavaScript linked to from a webpage. JavaScript embedded into a webpage will not be blocked.

> Sheriff is built upon Apple's Safari Content Blocker technology, which only blocks externally-loaded resources, like JavaScript and Cookies.

akyuu··on Bottlerocket – Minimal, immutable Linux OS with verified boot
In the GitHub issue, there is a mention of replacing rustls and Go's crypto library with OpenSSL. That seems like a serious security downgrade.
akyuu··on Bottlerocket – Minimal, immutable Linux OS with verified boot
It means there is a full trusted boot chain from the TPM to loading the immutable root filesystem: https://github.com/bottlerocket-os/bottlerocket/blob/develop...

Regular Linux distributions don't have this, even if Secure Boot is enabled: https://0pointer.net/blog/brave-new-trusted-boot-world.html

akyuu··on Bottlerocket – Minimal, immutable Linux OS with verified boot
On the GitHub repo (https://github.com/bottlerocket-os/bottlerocket), there are instructions for using it on VMware and bare metal:

https://github.com/bottlerocket-os/bottlerocket/blob/develop...

https://github.com/bottlerocket-os/bottlerocket/blob/develop...

akyuu··on Woman loses over $44k after downloading third-party app to buy fish
> Fortunately, the solution of just sticking to mainstream platforms works.

Well, it depends. For widespread non-targeted attacks, like the one mentioned in the parent comment, I think using a niche platform is a form of security through obscurity that can actually work, because it's possible the generic exploit you encounter is not designed to work on your non-standard system (like a virtual machine, a hardened configuration, a non-mainstream OS like OpenBSD...). Although this is more difficult on phones, because it's not possible to use some mainstream services on niche platforms due to attestation requirements.

akyuu··on Chromebooks will get 10 years of automatic updates
I have serious doubts about how comprehensive this support will actually be, especially regarding firmware updates and non-Google vendor commitment.

There is a wide variety of Chromebook hardware manufacturers, and most of them don't have a good track record of providing firmware upgrades for long. Google can keep ChromeOS updated on these devices, just like Microsoft can keep pushing Windows updates, but are the manufacturers going to provide firmware updates for 10 years? Are Intel or Mediatek going to be providing 10 years of microcode updates for the CPUs used on these devices? It doesn't make sense to me that these companies are suddenly going to invest a lot of money just to support these cheap devices that probably don't make a lot of profit, when they have never given a similar level of support to their flagship products.

I think this 10 year support window will not be full device support, just a commitment to providing OS updates that don't break stuff.

akyuu··on Linux Phones (2022)
There is plenty of software written in memory-unsafe languages that interacts with untrusted input: browsers are the most prominent example, but also email clients, media players, PDF viewers, archivers, IRC clients, torrent clients... not to mention all the network stack and firmware involved. iPhones and Pixels have many defense layers, both on software (sandboxing, JITCage...) and hardware (Secure Boot backed by root of trust, IOMMU for hardware isolation, PAC, PPL, MTE soon on Armv9...). The Linux desktop stack, including Linux phones, has none of this.

Linux phones might be good as a hackable/tinkering-friendly gadget, but they are definitely not secure.

akyuu··on How mobile apps illegally share personal data
There are several existing options:

- Windows: Simplewall (uses native WPF for filtering), Portmaster (interactive firewall, uses custom kernel extension).

- macOS: LuLu or Little Snitch (they all use a native filtering API, which unfortunately is not perfect: https://lapcatsoftware.com/articles/2023/6/3.html).

- Linux: OpenSnitch, denying network permission to Flatpak apps.

- Android: Rethink, NetGuard; GrapheneOS has app network permission natively.

iOS is the only OS where no application firewall is available, although if you don't use Wi-Fi, you can block apps from using cellular data.

akyuu··on Chrome: Heap buffer overflow in WebP
Do you have a source for that? AFAIK Pixel 7 uses an ARM v8.2 CPU, which doesn't support MTE. The upcoming Pixel 8 might support it, but Google hasn't announced anything yet.
akyuu··on Meduza co-founder's phone infected with Pegasus
Not really. Even with modern technologies, the Linux desktop technology stack is very, very far behind when it comes to security.

The Linux kernel itself is a very weak foundation security-wise, the only way Android and ChromeOS get away with it is by using a very small feature set and restricting everything else as much as possible with seccomp, SELinux and heavy sandboxing.

The Linux desktop userland doesn't have meaningful hardening features compared to other platforms (even Windows is ahead, sadly). For example, practically all distros use glibc's memory allocator which has both poor performance and security [1] and their toolchain is based on gcc, with no support for modern compiler security features such as CFI (with the sole exception of Chimera Linux). Not to mention the permission model is completely outdated, like in that xkcd comic. Flatpak only mitigates this partially, because the Flatpak sandbox is very weak. The people working on Flatpak are doing their best, but from reading some GitHub issues, it's clear they are badly overworked and not security experts. The person responsible for Flatpak's seccomp sandbox has said it isn't even his main responsibility and he doesn't have much knowledge about seccomp and is learning along the way [2]. The Flatpak seccomp filter is based on a denylist rather than an allowlist, and many dangerous syscalls can't be blocked because applications rely on them (e.g. Firefox needs ptrace for the crash reporter). You also have to be very careful and use Flatseal (which is not officially supported) to deny permissions such as /home filesystem access, because it lets Flatpak apps override their own permissions by design [3]. And dangerous kernel components like io_uring are exposed [4], while Google disables them on their systems because of their exploitation potential.

Here is a more detailed article examining the lack of security of Linux phones in case you're interested: https://madaidans-insecurities.github.io/linux-phones.html

If you want a FOSS-based secure phone, GrapheneOS is the best option.

[1] Check this comment by GrapheneOS founder for some technical details and how it compares to hardened allocators such as Android's Scudo or Graphene's hardened_malloc: https://github.com/NixOS/nixpkgs/issues/90147#issuecomment-6...

[2] https://github.com/flatpak/flatpak/issues/4466#issuecomment-...

[3] https://github.com/flatpak/flatpak/issues/3637

[4] https://github.com/flatpak/flatpak/issues/5447

akyuu··on A group of open source Android apps without ads and unnecessary permissions
The business model is simply selling the game (typically in a $10-60 range), and sometimes additional DLC (downloadable content).

There are many games by independent developers on consoles, too. For example, Nintendo regularly releases "Indie World Showcase" promotional videos: https://www.youtube.com/watch?v=brNLmMMB-J4

akyuu··on A group of open source Android apps without ads and unnecessary permissions
Nintendo consoles seem to provide the experience you're looking for. Clean and curated games with no ads or subscriptions. And the games tend to be of higher quality, focused on actual gameplay as opposed to the dark patterns common on phone apps (e.g. time-limited "stamina" and other psychological manipulation tricks to encourage addictive behavior).
akyuu··on NSO group iPhone zero-click, zero-day exploit captured in the wild
> I haven’t noticed any difference with web content either, but I also use Firefox / Chrome instead of Safari

Lockdown mode only affects Safari. If you use another browser, it doesn't make any difference.

Here are some features that are disabled in Safari when lockdown mode is enabled:

- JIT

- Remote fonts

- WebAssembly

- WebGL

- WebRTC

- PDF Viewer

- MP3 Playback

- Gamepad API

- Web Audio API

- Speech Recognition API

- MathML

- JPEG 2000

- MediaDevices.getUserMedia()

You can configure most of those in Firefox and Chrome, but it has to be done manually and cannot be disabled easily on a per-site basis like in Safari.

akyuu··on Google Chrome pushes browser history-based ad targeting
I'm not sure, but I think CFI also requires building Chromium as a single binary with LTO, and this has extremely high memory requirements that their build infrastructure might not be able to handle. Also, I think some distros use GCC instead of LLVM/Clang, so CFI isn't even an option.
akyuu··on Google Chrome pushes browser history-based ad targeting
IMO the browser is far too important to use third-party builds containing patches that don't receive serious audit.

For example, the Chromium packages provided by the vast majority of Linux distros disable security features like CFI (check your favorite distro's x86_64 Chromium package build log and look for the "is_cfi" argument). I think Arch is the only exception.

ungoogled-chromium has similar problems https://qua3k.github.io/ungoogled/

If you are going to use a Blink-based browser, I would recommend just using the official Google release, or maybe Edge or Brave if you trust the organizations behind them. Otherwise, just switch to Firefox. It has its own problems, like being overall less hardened than Chromium, but it's far less user-hostile. And regarding security, for browsing untrusted sites, I think you should always virtualize the browser since they're all routinely exploited anyway.

akyuu··on Browser extensions spy on you, even if its developers don't
NextDNS and AdGuard DNS are just DNS providers that return filtered results for ad-related DNS queries. Their filter lists are public:

https://github.com/orgs/nextdns/repositories?type=all

https://github.com/AdguardTeam/AdGuardSDNSFilter

If you don't trust their DNS servers for whatever reason, you can simply add these entries to your hosts file to replicate their functionality locally.

akyuu··on Browser extensions spy on you, even if its developers don't
You can also use a declarative adblocker like uBlock Origin Lite [1], which only provides the browser with a list of elements to filter, but doesn't have any permissions to read content or perform requests. Or simply use your hosts file to apply OS-wide filtering with no browser add-ons needed [2].

Be aware that if you use these "passive" blocking methods, there are some sites like YouTube where you will see ads, because in these cases it's necessary to actually manipulate page content to hide them. What you can do is use a traditional adblocker but enable it only for these few sites where the declarative approach is not enough, take a look at [3] for more details.

[1] https://github.com/uBlockOrigin/uBOL-home

[2] https://github.com/StevenBlack/hosts

[3] https://seirdy.one/posts/2022/06/04/layered-content-blocking...

akyuu··on Doas – dedicated OpenBSD application subexecutor
You might find this interesting: https://www.memorysafety.org/blog/sudo-first-stable-release/
akyuu··on 5 years ago Valve released Proton
Could you list some examples of such hardware? I'm interested.
akyuu··on uBlock Origin Lite now available on Firefox
If you use a non-declarative adblocker, you're not just trusting the developer, but also all the third-party filter lists you've subscribed to. These filters have powerful capabilities and can even exfiltrate website data [1], and they are updated in real time, so if a bad actor pushed a malicious update (e.g. by gaining access to any EasyList contributor account), you would most likely be affected.

However, it's true some websites (like YouTube) are especially problematic and a declarative adblocker is not enough. What you can do is combine both approaches: use a declarative adblocker (uBlock Origin Lite) as a baseline, and selectively enable non-declarative adblockers (uBlock Origin) for specific websites (see [2] for a detailed overview).

I like this layered approach because it gets you the best of both worlds: the security and performance of a declarative adblocker, and the functionality of a non-declarative adblocker when you need it, without compromising your entire browsing session.

[1] https://portswigger.net/research/ublock-i-exfiltrate-exploit...

[2] https://seirdy.one/posts/2022/06/04/layered-content-blocking...

akyuu··on Zenbleed
It can be exploited through JavaScript according to CloudFlare: https://blog.cloudflare.com/zenbleed-vulnerability/
akyuu··on Zenbleed
What about running JavaScript on a browser?
akyuu··on Zenbleed
Not sure if they're actually fine, some researchers have exploited this vulnerability on AWS instances that use affected EPYC CPUs: https://twitter.com/0xdabbad00/status/1683581484337348608
akyuu··on Zenbleed
https://www.amd.com/en/resources/product-security/bulletin/a...

According to AMD's security bulletin, firmware updates for non-EPYC CPUs won't be released until the end of the year. What should users do until then, disable the chicken bit and take the performance hit?

akyuu··on Linux has nearly half of the desktop OS Linux market
> for most people in most cases that's akin to putting a bank vault door on the front of your house

If we are talking about a device in which you do banking, shopping, manage sensitive or work data, etc. then I think security should be a priority. For more casual use, I agree Qubes would be overkill.

> Which one are you choosing?

I'd rather execute Setup.exe inside Windows Sandbox or denying UAC prompts, or a random macOS binary (provided SIP is not disabled) than a Flatpak. To be clear, I think Flatpak is an improvement, I'm glad it exists and I hope it continues evolving. But in my opinion, the Linux desktop still has a long way to catch up to Windows and macOS on security.

akyuu··on Linux has nearly half of the desktop OS Linux market
In my previous reply, I linked three articles which discuss the technical details extensively:

https://madaidans-insecurities.github.io/linux.html

https://privsec.dev/posts/linux/linux-insecurities/

https://bjornpagen.com/en_US/desktop%20linux%20is%20insecure

A brief summary: No trusted boot, no clear security boundaries between system and applications, no application sandboxing, lack of mitigations (both on kernel and userspace), large kernel attack surface, insecure-by-design legacy systems (X, PulseAudio). Windows and macOS perform comparatively better on all of those.

akyuu··on Web Environment Integrity Explainer
The first use case they mention is restricting ad fraud (and, presumably, ad blocking):

> Users like visiting websites that are expensive to create and maintain, but they often want or need to do it without paying directly. These websites fund themselves with ads, but the advertisers can only afford to pay for humans to see the ads, rather than robots. This creates a need for human users to prove to websites that they're human, sometimes through tasks like challenges or logins.

So if this goes forward, websites will be able to call the web environment integrity API to check you are a proper ad-watching human before serving content.

akyuu··on Google Chrome Proposal – Web Environment Integrity
On the explainer page [1], the first use case example is to prevent ad fraud (and, presumably, ad blocking...):

> Some examples of scenarios where users depend on client trust include:

> Users like visiting websites that are expensive to create and maintain, but they often want or need to do it without paying directly. These websites fund themselves with ads, but the advertisers can only afford to pay for humans to see the ads, rather than robots. This creates a need for human users to prove to websites that they're human, sometimes through tasks like challenges or logins.

So it's essentially Google further entrenching its tentacles in web standards in the most invasive ways with no regards towards privacy and user control. It's a shame what the W3C has degenerated into.

[1] https://github.com/RupertBenWiser/Web-Environment-Integrity/...

akyuu··on Linux has nearly half of the desktop OS Linux market
Flatpak permissions are very broad by default in most applications. Even if you manually override them by using Flatseal, some permissions like X.org or PulseAudio sockets are very problematic because these legacy protocols are not designed to be secure. Even if you manage to lock down permissions and only use modern apps that support Wayland and Pipewire, the Flatpak sandbox still exposes a lot of kernel attack surface because it blocks very few syscalls. I think they should add something similar to Win32k lockdown (ProcessSystemCallDisablePolicy) on Windows and disable insecure components like io_uring.

As for immutable distros, AFAIK Silverblue and others are immutable in the sense of package management, but there is actually no process to ensure the integrity of the full boot chain because initrd can be trivially modified by the host and is unsigned. There is a UKI (Unified Kernel Image) proposal that will likely be the path going forward (at least on the Red Hat world), but I think it's still years away.

In my opinion, if you want to use Linux desktop securely, just use Qubes.

akyuu··on Linux has nearly half of the desktop OS Linux market
Compared to the other desktop operating systems (Windows and macOS), it absolutely is. It might have other advantages, but security is not one of them, and users should be aware.
← PreviousPage 2 of 3Next →