Skip to content
Merged
Show file tree
Hide file tree
Changes from 56 commits
Commits
Show all changes
58 commits
Select commit Hold shift + click to select a range
c280fcf
fix(config.yml): change gh_edit_branch to master
Thrilleratplay Sep 11, 2020
dce5bb4
chore: format according to markdownlint
Thrilleratplay Sep 12, 2020
6132efd
docs(community): move slack info to community page
Thrilleratplay Sep 12, 2020
97d1cd1
fix: image location to reference site url to prevent incorrect relati…
Thrilleratplay Sep 12, 2020
0771f80
docs: add structure and copy heads related pages from trmm.net
Thrilleratplay Sep 13, 2020
1899083
docs(HeadsThreatModel): update archived links
Thrilleratplay Sep 13, 2020
0199d89
docs(Community): update Slack channel descriptions
Thrilleratplay Sep 14, 2020
ff0b258
docs(Community): add links to github issues and bounty/helpwanted tags
Thrilleratplay Sep 14, 2020
1c876bc
docs(GPG): Remove dated GPG version mention
Thrilleratplay Sep 14, 2020
ddca65d
docs(Building): Remove incorrect x220 reference mention
Thrilleratplay Sep 14, 2020
d0216c3
docs(Development): add links to github issues and bounty/helpwanted tags
Thrilleratplay Sep 14, 2020
6ee51be
docs(PDFs): Add referenced PDFs to repo
Thrilleratplay Sep 18, 2020
8df7f94
chore: remove bootgaurd and influences
Thrilleratplay Sep 18, 2020
090861f
docs(FAQ): add reference to bootgaurd
Thrilleratplay Sep 18, 2020
c5da46f
docs(headsThreatModel): move influnces references into threat model
Thrilleratplay Sep 18, 2020
1a3a50d
chore: fix linting errors
Thrilleratplay Sep 18, 2020
a4dabc9
docs(FlashingGuides): add flashing guides
Thrilleratplay Sep 18, 2020
9716fc0
docs(BeginnerInstallGuide): move x230 flashing info to x230 flashing …
Thrilleratplay Sep 18, 2020
2ae88c2
fix(kpge-d16): correct permalink
Thrilleratplay Sep 18, 2020
5f059a0
chore(About): move Brief overview of Heads files under About
Thrilleratplay Sep 27, 2020
6f584c1
docs(porting): add CBFS information
Thrilleratplay Sep 27, 2020
3af8cef
docs(index): readd link to FAQ and required equipment
Thrilleratplay Sep 27, 2020
1b57a6e
docs(Tioga): add link to coreboot docs
Thrilleratplay Sep 27, 2020
a7e4cba
docs(MakeDetails): move Makefile details to Development section
Thrilleratplay Sep 28, 2020
51178ed
docs(InstallingAndConfiguring): list device details and requirements
Thrilleratplay Sep 28, 2020
2e6e655
docs(InstallingAndConfiguring): break down install documents into dif…
Thrilleratplay Sep 28, 2020
ce55dbb
docs(FlashinGuides): remove unused pages
Thrilleratplay Oct 2, 2020
ec2eb4b
docs(InstallingAndConfiguring): consolidate documents
Thrilleratplay Oct 2, 2020
8dc636a
docs(images): add pictures of gui-init
Thrilleratplay Oct 2, 2020
ae1c00c
chore(Development): lint Development markdown
Thrilleratplay Oct 2, 2020
d3073ba
chore(index): fix markdownlint errors
Thrilleratplay Oct 2, 2020
70b21a7
docs(InstallingAndConfiguring): update configuring keys
Thrilleratplay Oct 2, 2020
0caf132
chore: update image site base url
Thrilleratplay Oct 2, 2020
7d959f8
chore: update image site relative url
Thrilleratplay Oct 2, 2020
9960766
chore: revert update image site relative url
Thrilleratplay Oct 2, 2020
d1a5573
docs(index): remove old information
Thrilleratplay Oct 3, 2020
307dd50
docs(HeadsThreatModel): remove ref tag
Thrilleratplay Oct 3, 2020
a8675bb
docs(Development): update board information
Thrilleratplay Oct 3, 2020
c7a1c11
docs(InstallAndConfiguring): use phase 'USB security dongle'
Thrilleratplay Oct 3, 2020
2dca122
docs(Porting): link to me cleaner docs about resizing
Thrilleratplay Oct 3, 2020
32634b3
docs(InstallAndConfiguring): make requested changes
Thrilleratplay Oct 3, 2020
817dd84
docs(InstallAndConfiguring): make requested changes
Thrilleratplay Oct 3, 2020
6a64488
docs(InstallAndConfiguring): specify certian devices are HOTP compatable
Thrilleratplay Oct 3, 2020
9731de6
docs(InstallAndConfiguring): make requested changes
Thrilleratplay Oct 3, 2020
64821da
docs(InstallAndConfiguring): removed releases section
Thrilleratplay Oct 3, 2020
5f9705c
docs(InstallAndConfiguring): make requested changes
Thrilleratplay Oct 3, 2020
9f249ae
docs(InstallAndConfiguring): make requested changes
Thrilleratplay Oct 3, 2020
1346160
docs(InstallAndConfiguring): make requested changes
Thrilleratplay Oct 3, 2020
1a45680
docs(Keys): make requested changes
Thrilleratplay Oct 4, 2020
3f36b4c
docs(Porting): make requested changes
Thrilleratplay Oct 4, 2020
d585b21
docs(InstallAndConfiguring): make requested changes
Thrilleratplay Oct 4, 2020
ee90a62
docs(Keys): make requested changes
Thrilleratplay Oct 4, 2020
7352804
docs(Porting): fix typo
Thrilleratplay Oct 12, 2020
3cac423
docs(Building): fix ungood English
Thrilleratplay Oct 12, 2020
4bd133d
chore: add favicon
Thrilleratplay Oct 14, 2020
446dee7
fix: update link redirects
Thrilleratplay Oct 14, 2020
2c8e089
docs(HeadsThreatModel): add write protection information
Thrilleratplay Oct 14, 2020
59aae06
docs(HeadsThreatModel): minimize write protection information
Thrilleratplay Oct 19, 2020
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
193 changes: 193 additions & 0 deletions About/FAQ.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,193 @@
---
layout: default
title: FAQ
permalink: /FAQ/
nav_order: 1
parent: About
---

FAQ
{: .fs-8 .m-0 }

Heads is an open source firmware, OS configuration and hardware hardening guide
for building slightly more secure systems. Installing Heads requires opening
the machine and extensive warranty voiding, so this document tries to answer
some of the questions about it.

<!-- markdownlint-disable MD033 -->
<details open markdown="block">
<summary>
Table of contents
</summary>
{: .text-delta }
1. TOC
{:toc}
</details>
<!-- markdownlint-enable MD033 -->

<!-- markdownlint-disable MD002 -->

Why replace UEFI with coreboot
----

While Intel's edk2 tree that is the base of UEFI firmware is open source, the
firmware that vendors install on their machines is proprietary and closed
source. Updates for bugs fixes or security vulnerabilities are at the vendor's
convenience; user specific enhancements are likely not possible; and the code
is not auditable.

UEFI is much more complex than the BIOS that it replaced. It consists of
millions of lines of code and is an entire operating system, with network
device drivers, graphics, USB, TCP, https, etc, etc, etc. All of these features
represents increased "surface area" for attacks, as well as unnecessary
complexity in the boot process.

coreboot is open source and focuses on just the code necessary to bring the
system up from reset. This minimal code base has a much smaller surface area
and is possible to audit. Additionally, self-help is possible if custom
features are required or if a security vulnerability needs to be patched.

What's wrong with UEFI Secure Boot
----

Can't audit it, signing keys are controlled by vendors, doesn't handle hand off
in all cases, depends on possible leaked keys.

Why use Linux instead of vboot2
----

vboot2 is part of the coreboot tree and is used by Google in the Chromebook
system to provide boot time security by verifying the hashes on the coreboot
payload. This works well for the specialized Chrome OS on the Chromebook, but
is not as flexible as a measured boot solution.
By moving the verification into the boot scripts we're able to have a much
flexible verification system and use more common tools like PGP to sign
firmware stages.

What about Trusted GRUB
----

The mainline grub doesn't have support for TPM and signed kernels, but there is
a Trusted grub fork that does. Due to philosophical differences the code might
not be merged into the mainline. And due to problems with secure boot (which
Trusted Grub builds on), many distributions have signed insecure kernels
that bypass all of the protections secure boot promised.
Additionally, grub is closer to UEFI in that it must have device drivers for
all the different boot devices, as well as filesystems. This duplicates the
code that exists in the Linux kernel and has its own attack surface.

Using coreboot and Linux as a boot loader allows us to restrict the signature
validation to keys that we control. We also have one code base for the device
drivers in the Linux-as-a-boot-loader as well as Linux in the operating system.

What is the concern with the Intel Management Engine
----

* ["Rootkit in your laption" (PDF)]({{ site.baseurl }}/PDFs/Rootkit_in_your_laptop.pdf)
by Igor Skochinsky of Hex-Rays, Breakpoint 2012 Melbourne
* ["Intel ME Secrets" (PDF)]({{ site.baseurl }}/PDFs/Recon_2014_Skochinsky.pdf) by
Igor Skochinsky of Hex-Rays, RECON 2014 Montreal
* ["x86 considered harmful" (PDF)]({{ site.baseurl }}/PDFs/x86_harmful.pdf) by
Joanna Rutkowska, October 2015

How about the other embedded devices in the system
----

* ["Hardening hardware and choosing a #goodBIOS"](https://media.ccc.de/v/30C3_-_5529_-_en_-_saal_2_-_201312271830_-_hardening_hardware_and_choosing_a_goodbios_-_peter_stuge#t=2372)
by Peter Stuge, 2013
* [Funtenna uses software to make embedded devices broadcast data on radio frequencies](http://www.slate.com/blogs/future_tense/2015/08/05/_funtenna_uses_software_to_make_embedded_devices_broadcast_data_on_radio.html)
by Ang Cui 2015

Should we be concerned about the binary blobs
----

Maybe. x230 has very few (MRC) since it has native vga init.

Why use ancient Thinkpads instead of modern Macbooks
----

The x230 Thinkpad has coreboot support, TPM, nice keyboards and are very cheap
to experiment on. If you're willing to spend a bit more, the Chell Chromebooks
(commericaly available as the HP Chromebook 13 G1) has Skylake. Newer
[Thinkpads contain Bootguard](https://mjg59.dreamwidth.org/33981.html), a
closed source security function implemented by Intel to prevent unsigned custom
firmware, such as coreboot and heads, from being installed.

How likely are physical presence attacks vs remote software attacks
----

Who knows.

Defense in depth vs single layers
----

Yes.

is it worth doing the hardware modifications
----

Depends on your threat model.

Should I validate the TPMTOTP on every boot
----

Probably. I want to make it also do it at S3. [See Heads issue #69](https://github.com/osresearch/heads/issues/69)

suspend vs shutdown
----

S3 is subject to cold boot attacks, although they are harder to pull off on a
Heads system since the boot devices are constrained.

However, without tpmtotp in s3 it is hard to know if the system is in a safe
state when the xscreensaver lock screen comes up. Is it a fake to deceive you
and steal your login password? Maybe! It wouldn't get your disk password,
which is perhaps an improvement.

Disk key in TPM or user passphrase
----

Depends on your threat model. With the disk key in the TPM an attacker would
need to have the entire machine (or a backdoor in the TPM) to get the key and
their attempts to unlock it can be rate limited by the TPM hardware.
However, this ties the disk to that one machine (without having to recover and
type in the master key), which might be an unacceptable risk for some users.

Why is it called Heads
----

*The flip side of [Tails](https://tails.boum.org/).*

Unlike [Tails](https://tails.boum.org/), which aims to be a stateless OS that
leaves no trace on the computer of its presence, Heads is intended for the
case where you need to store data and state on the computer.

HOTP vs TOTP
----

HOTP (HMAC-based One-time Password algorithm) generates a password
using hash-based message authentication codes (HMAC) that can be used only for
the one authentication attempt. Uniqueness is based on a counter which is
incremented each authentication attempt.

TOTP (Time-based One-time Password algorithm) is an extension of HOTP but
replaces the counter with time. Because of latency, both network and human,
and unsynchronised clocks, the one-time password must validate over a range of
times between the authenticator and the user. Here, time is
downsampled into larger durations (e.g., 30 seconds) to allow for validity
between the parties.

Secuirty wise, HOTP is more susceptible to brute force attacks without
throttling or limiting the number of failed attempted while TOTP is susceptible
to phishing attacks and requires a user to enter the code within a given time
period.

coreboot vs Linuxboot
----

TO BE WRITTEN

What happens if I lose/break my security key
----

TO BE WRITTEN
Loading