Discussion on Purism

As I pointed before @TommyTran732 and to anyone thinking compromising measured boot is trivial, I layed down the tooling for anyone wanting to further protection / prove measured boot not enough to understand and break it once and for all under WiP: introspection - replicate TPM PCRs measurements directly from measured content (TCPA/TPM Event log) by tlaurion · Pull Request #1568 · linuxboot/heads · GitHub

Just use it for the bad to faster the development of something good/better.

Until then, it was proven non trivial. You refusing to read it, test it, prove you understand how a TPM extend/seal/unseal/quote ops work, extract/replay/tamper bootblock anchored measured boot is yet to be proven flawed beyond just theoretical attack by anyone/to everyone. Please just do it and like I said: you’ll get the world’s attention. Until then, you are in denial. And this echo chamber is not the place (not my place) to discuss this further.


EDIT: added repro notes directly at WiP: introspection - replicate TPM PCRs measurements directly from measured content (TCPA/TPM Event log) by tlaurion · Pull Request #1568 · linuxboot/heads · GitHub to entice Evil-Made PoC by anyone willing to take that challenge to move theoretical vuln into a practical, reproducible PoC. Up for the challenge with more than words but code? PLEASE DO IT.

2 Likes

And again, for the sake of this thread, I already replied extensively with my own learnings and criticisms at "Maybe I messed up my qubes installation?" related support questions involving "some" Heads subtleties, aka "How to disable autostarting of service qubes at boot without Grub interface" - #8 by Insurgo

(tags: firmware, testing, security, Purism, QubeOS certification process, oem disk installation, salt, kick-start what should be the next steps, where collaboration is needed etc etc etc)

2 Likes

Do you have the corresponding video?

2 Likes
2 Likes

Direct video link:

2 Likes
I moved this topic to the #all-around-qubes category due to these posts:

If @moderators and/or trust level 3/Regular users would rather prefer the topic goes back into the General Discussion category, simply move it again.

access to category

Isn’t “All around Qubes” somehow access-restricted?
[After checking] → yes it is:

2 Likes
Moved back to `General Discussion`.

It doesn’t seem appropriate to move this mega-thread after all this years. As @fsflover outlined: this is hardware specifically marketed towards Qubes OS users and their experiences and impressions with the vendor are on-topic.

2 Likes

Sure, although Purism primarily targets PureOS, not Qubes OS.

How can I know if the glitter nail polish is acryllic or gel?
I’ve had a very bad experience trying to ask questions about glitter nail polish at local stores that sell glitter nail polish. They always answer “don’t know”.

1 Like

At a glance, thickness of the applied polish is a giveaway. Gel is thicker while acrylic is thinner.

2 Likes

Gel is thicker while acrylic is thinner.

As a straight guy, I wouldn’t know :man_shrugging: :nail_care: :laughing:

1 Like

Trammel recommended this brand. Shipped all privacy beast with it. Worked awesome.

3 Likes