HNHacker News
TopNewBestAskShowJobs

mkopec

182 karma · joined August 6, 2021

Open-source firmware engineer.

All opinions mine unless expressly stated otherwise.

submissionscomments
mkopec··on TrenchBoot DRTM Launch of Xen on Intel Sapphire Rapids
Platform: ASRock Rack SPC741D8, Xeon Sapphire Rapids. Firmware: Dasharo, coreboot + edk2 payload. Launch path: GETSEC[SENTER] with the SINIT ACM, Xen and dom0 measured into PCRs 17-18.
mkopec··on Microsoft deletes official Windows 11 CPU/TPM bypass for unsupported PCs
> If all DVD players came with watermark detection instead of copy protection

That is an enormous "if". Do you think Microsoft is going to or is able to enforce this on every single software provider? Even in your Android example that's just not happening, and you can happily sideload apps. You can still develop your own apps on the same Android phone that you use for banking.

> And sorry but how many people have bypassed Playstations or Switches. This is what you’re talking about. Most people will just accept it.

People accept this with consoles because a console is a device exclusively for consuming media, and all developers apply for a devkit. I just don't see that happening in the PC space. You think Microsoft is suddenly going to dump this on third party software developers and force everyone to go through certification and to buy devkits? Without a mass exodus to Linux?

mkopec··on Microsoft deletes official Windows 11 CPU/TPM bypass for unsupported PCs
Google SafetyNet is basically swiss cheese with lots of bypass solutions for custom ROMs.

A TPM may only attest that it has received an expected set of measurements (hashes). As long as discrete TPMs or PCs with unlocked CPUs exist (w/o Boot Guard), one may simply take a TPM and replay "golden" measurements to it. Bypassing this would be trivially easy.

A TPM does not have control over execution on the CPU. It only receives data from the CPU. If you have control over execution on the CPU from the reset vector, you can just replay whatever you want to a TPM and extract secrets that way. That's why TPM backed disk encryption without configuring a PIN is insecure.

Microsoft does not have the same level of control over the entire PC ecosystem as Google has over Android. That's why it's important to support open source alternatives.

mkopec··on Microsoft deletes official Windows 11 CPU/TPM bypass for unsupported PCs
Widevine L1 requires a trusted execution environment for decrypting video and only showing it on HDCP monitors. It's built on top of Intel PAVP, AMD secure display, or ARM TrustZone in the case of ARM chromebooks and Android devices. TPM is not involved, except in the ARM case where I believe it is used for antirollback counters (on x86, the security coprocessor would probably have that responsibility).
mkopec··on Microsoft deletes official Windows 11 CPU/TPM bypass for unsupported PCs
> Does TPM support/requirements actually have any meaningful impact on a home user?

Disk encryption, Windows Hello and PIN bruteforce prevention. I have no love Microsoft and avoid using Windows whenever I can, but I think making those features accessible to more people is a good thing.

mkopec··on Microsoft deletes official Windows 11 CPU/TPM bypass for unsupported PCs
There are none. It's so immensely frustrating to me that so many people believe that a TPM is a DRM device. I'm sure Richard Stallman's Treacherous Computing article played a big part in this.

A TPM is useless for DRM, and there are way more suited solutions like Intel's PAVP that takes an encrypted video stream and puts it on the screen directly, yet I don't see nearly as much uproar about that.

mkopec··on Spotify Car Thing will be discontinued
I think if the process was made easy, it would save quite a bit more than 1% of these devices from the landfill, assuming you have enough power users to build a community. Plenty of people flash their chromebooks to MrChromebox UEFI to give them a new life, because it's easy enough for mere mortals, and because Google doesn't lock them down.

I believe if given the tools, people would gladly donate their time to make something fun with it. Heck, that's what I do in my spare time. But it's impossible if everything is completely locked down, as if a music streaming box contains nuclear launch codes that must be protected at all costs.

mkopec··on Spotify Car Thing will be discontinued
I firmly believe that permanent key fusing to lock bootloaders should be outlawed. At the very least the keys (and schematics) should be released once the device reaches EOL.

Otherwise we're just manufacturing e-waste.

mkopec··on When children become caregivers, who cares for them?
Yeah, that's not something anyone should be saying to random people online.
mkopec··on DNS traffic can leak outside the VPN tunnel on Android
Do Android Auto and VoLTE / VoWiFi work on Graphene these days? I also remember Google Maps and Uber being extremely problematic
mkopec··on Gaining kernel code execution on an MTE-enabled Pixel 8
Application Processor, i.e. the main processor
mkopec··on PixieFail: Nine Vulnerabilities UEFI Implementations
I would like to be able to ensure that only boot loaders signed with my private key can be executed. Secure Boot serves that purpose well, can I do that with your approach?

Likewise, demand and use cases for network boot exist, otherwise it wouldn't be here. Same goes for every other feature most users would consider bloat.

mkopec··on PixieFail: Nine Vulnerabilities UEFI Implementations
Rust won't magically fix every vulnerability and someone would have to pay a team of engineers to rewrite everything.
mkopec··on PixieFail: Nine Vulnerabilities UEFI Implementations
Some piece of code has to configure the CPU, initialize memory before you can even think about loading an OS...
mkopec··on Inside the Steam Deck's APU
All Zen 1 CPUs and newer have the PSP / ASP security processor which is ARM based and runs before the x86 cores are released from reset. This applies to all Zen models, not just the PRO versions.

The fTPM does indeed run on the PSP, so on the ARM cores, among many other things like DRAM training.

mkopec··on DaedalOS – Desktop environment in the browser
I think ChromeOS Freon was close to what you're describing, but they ended up switching to Wayland at some point
mkopec··on Linux and TPMs with systemd measured boot [video]
Dropping a link to a project attempting to create a fully open source TPM: https://twpm.dasharo.com/
mkopec··on Linux and TPMs with systemd measured boot [video]
In what manner specifically does a TPM not belong to the user, while a YubiKey does?
mkopec··on 999 Request Denied
Right, but then the crawler devs will google this weird 999 code and handle it as a 429.

If I wanted to mess with clients I don't like, I'd just return a random valid code.

mkopec··on Show HN: A little script to check if your Ryzen PC uses Platform Secure Boot
Disappointed with Lenovo's decision to enable PSB on my T14, having previously hoped one day I'd run coreboot on it, I decided to write a checker and crowdsource a list of PSB-enabled devices so that others may avoid buying hardware that disallows custom firmware.
mkopec··on VeraCrypt: Free open-source disk encryption for Windows, Mac OS X, Linux
Indeed, it seems that having another unlock option might be preferable. If you value your own live over the secrets, that is.
mkopec··on VeraCrypt: Free open-source disk encryption for Windows, Mac OS X, Linux
It's a matter of priorities, I guess?

If you want to you can just not save the recovery password. In that case I guess they'll just beat you to death with that $5 wrench.

mkopec··on VeraCrypt: Free open-source disk encryption for Windows, Mac OS X, Linux
With LUKS you can enroll an extra auth option in addition to TPM, like a password or a FIDO2 token.
mkopec··on Framework Laptop Cupholder Expansion Card
Well you can't hack the firmware :( A baffling decision considering the brilliant work they're doing otherwise. I do not see a reason why they absolutely need to have Intel Boot Guard enabled.

I'm at the point where I'm not even looking for laptops with coreboot OOTB, I just want a good laptop that is not fused to the vendor's keys. I'll port coreboot to it myself.

mkopec··on OpenWRT 22.03.4
I imagine with a sufficient power supply it should not be a problem, at least I haven't had any problem with mine yet. I have a friend who's using one of their DBDC cards in an apu2 and he also hasn't had power issues yet.

> One more thing - how is the signal range for you?

With four 5dBi antennas it's sufficient to have >800mbps in every corner of my single bedroom apartment. Other than that I have no means to test, sorry :)

mkopec··on OpenWRT 22.03.4
I've got this one from AsiaRF: https://www.asiarf.com/shop/wifi-wlan/wifi_mini_pcie/wifi6-4... . OpenWRT has drivers for it in the repository, so it's pretty simple to set up.

I'm happy with it, but I did have to get a heatsink for it, since otherwise it overheats easily. Since I got it they released a couple of dual-band dual-concurrent cards like this one: https://www.asiarf.com/shop/wifi-wlan/wifi_mini_pcie/wifi6e-... , which is pretty neat, since you don't need to get a separate card for 2.4GHz devices.

mkopec··on PC Engines EOL
It is perhaps cheaper to use an existing design instead of designing a special one for embedded applications. In fact the GX-415GA with an iGPU looks like the exact same package as the GX-412TC, the GPU is probably just not fused off.
mkopec··on PC Engines EOL
I wonder if in pursuit of outright performance, AMD stopped optimizing for low power consumption. Desktop Zen3 Vermeer (which the newly announced 5000E series also are) with chiplets idles at around 20 watts, presumably due to having to maintain signal integrity between the chiplets. Similar story with the chiplet-based RDNA3 cards idling at 100W. Anecdotally, my Renoir laptop is also lacking in battery life.
mkopec··on Making a Linux home server sleep on idle and wake on demand – the simple way
Interesting. I believe with runtime (opportunistic) S0ix on x86 we'd be able to get similarly low power consumption at idle, but that would require cooperation from all devices and system firmware. It's already a thing on laptops, where if certain conditions are met, the laptop can technically be "sleeping" when the screen is displaying static content, like a document.
mkopec··on OpenWRT 22.03.4
Probably depends on the ISP and what sort of ONT we're talking. My ISP gives me a separate ONT with an ethernet connection for the router. In OpenWRT I set up a PPPoE interface on top of a tagged VLAN with the appropriate credentials and it works pretty well, I can get a public IP or an entire IPv6 prefix depending on cretendials.

I honestly don't know why they bother with this PPPoE + VLAN setup on top of a modern fiber network, but it is what it is.

You could probably get an ONT in an SFP package, if you want to eliminate a separate box. The problem there is that ISPs tend to have an allowlist of permitted ONTs on the network. Some ONTs allow you to change the serial number so that may work in place of the ISP box.

Page 1 of 2Next →