mathstodon.xyz is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for maths people. We have LaTeX rendering in the web interface!

Server stats:

2.7K
active users

#goldenkeyboot

0 posts0 participants0 posts today
Replied in thread

@hon1nbo @foone yeah, but all these things would essentially necessitate a fundamentally incompatible #Fork of the #USB standard, creating #costs, #fragmentation and lessen the likelyhood of success.

  • Not to mention it'll require significant investments in #UserAwareness, #Training and would still have some issues...

I gues a sort-of "Secure HID Port" that mandates proper authentification and does full #E2EE from the Keyboard Matrix / Pointing Device controller up is an option, but you'd have to expect state-sponsored attackers willing to do "Kamikaze" Hacks...

#TLDW: It requires custom silicon and a hard root of trust

infosec.space/@kkarhan/1137164

Replied in thread

@puppygirlhornypost2 @navi And whilst it's easy to blame #GoldenKeyBoot, a leaked #PrivateKey that was impossible to be removed, the problem is that #Windows is architecturally "insecure-able" because any changes necessary to make this not a problem would inherently mean the end for Windows as it's known to most.

  • In fact, everything is done better by #Linux on the #Desktop for almost two decades, which is why classic #Malware isn't a thing on Linux systems.

Shure, you get some #Cryptojacking and some #CMS|es like #WordPress that are constantly being attacked but generally, the way #updates and #distribution of #Software works on Linux Distros for the most part is completely antithetical to Windows.

And anything #Microsoft could do at this point if they weren't horny for money but avtually cared is to scrap Windows and instead invest into #Wine to ease the transition...

Replied in thread

@bedast My problem is that these people refuse to take the correct consequences and migrate away from garbage:

  1. You just don't install such garbage on #Unix-esque Systems like #Linux!

  2. #CrowdStrike is just yet another #Scareware #Scam.

  3. The entire business model of #AntiVirus and other Scareware shouldn't exist to begin with.

  4. 3rd party #BinaryBlobs on a non-#FLOSS'd kernel are just bad!

  5. It should be #Microsoft's sole tesponsibility to just not allow #Rootkits / #Bootkits like that to exist eith their blessing aka. #Signature on.

  6. #Windows & #WindowsServer are unbelieveably #cursed and unmaintainable mess that'll make even #Solaris 7 look clean and sleek.

  7. The diversity of Linux and Unix-esque distros like #BSD's make it basically impossible to bmhave such a giant and direct effect.

  8. The whole issue should've been avoided throug extensive testing because it's certainly so rampant that it would've been picked up by #QA testers.

  9. The fuckedup-ness of #CensorBoot aka. "#SecureBoot" (which is insecure af - see #GoldenKeyBoot!) is the reason why this results in such catastrophic failures, whereas on #Linux one just uses #LUKS and can easily recover files.

  10. Most Windows users & -#sysadmins neglect #Backups of Windows machines because there is no good way to backup them!

  11. 3rd party kernel binaryblobs are #malware, regardless if "Anti-Malware" or "#AntiCheat" is the claimed functionality.

  12. If I don't trust #WindowsDefender then I don't trust Windows or rather Microsoft and thus have to cease using it!

  13. This shit would not have been possible under Linux!

Nondeterministic ComputerMatthew Garrett (@mjg59@nondeterministic.computer)"Linux would have prevented this!" literally true because my former colleague KP Singh wrote a kernel security module that lets EDR implementations load ebpf into the kernel to monitor and act on security hooks and Crowdstrike now uses that rather than requiring its own kernel module that would otherwise absolutely have allowed this to happen, so everyone please say thank you to him
Replied in thread

@Quinnypig the sheer fact that #Microsoft and #Windows11 ain't banned across the #EU to this day is an indictment to the #TechIlliteracy of politicans in the @EUCommission & @europarl_en despite

and now

And since @GossiTheDog managed to get it running on a system w/o "#AI" acceleration aka. "#NPU" it's safe to assume that it'll be perfectly possible to retroactively shove it down everyones' throats without recourse!

  • Actually there are options for recourse besides "#ThoughtsAndPrayers" that regulators like @bsi would actually take this seriously:

Like: Stop using #Windows and get some help migrating away from it to a good #Linux distro!

Fixes a critical backdoor in Windows' CryptoAPI, which allows to unconsenting Update of CA Certificates in the background. See https://www.heise.de/ct/ausgabe/2013-17-Zweifelhafte-Updates-gefae...
GitHubGitHub - kkarhan/windows-ca-backdoor-fix: Fixes a critical backdoor in Windows' CryptoAPI, which allows to unconsenting Update of CA Certificates in the background. See https://www.heise.de/ct/ausgabe/2013-17-Zweifelhafte-Updates-gefaehrden-SSL-Verschluesselung-2317589.htmlFixes a critical backdoor in Windows' CryptoAPI, which allows to unconsenting Update of CA Certificates in the background. See https://www.heise.de/ct/ausgabe/2013-17-Zweifelhafte-Updates-gefae...