Elvith Ma'for

Former Reddfugee, found a new home on feddit.de. Server errors made me switch to discuss.tchncs.de. Now finally @ home on feddit.org.

Likes music, tech, programming, board games and video games. Oh… and coffee, lots of coffee!

I � Unicode!

  • 0 Posts
  • 11 Comments
Joined 2 years ago
cake
Cake day: June 21st, 2024

help-circle



  • Google Groups allows spammers to subscribe you to their groups in a workspace account, but doesn’t allow you to unsubscribe since you’re not part of that workspace account… Worse - all autoresponders for the spam will also be forwarded to all members of said group.

    Since I do not participate in Google Groups, the nuclear option is to file all mails from Google Groups as spam with a Sieve script.

    Note the require part may be too large as may sieve script also contains more rules than this one.

    require ["body", "date", "editheader", "envelope", "fileinto", "imap4flags", "mailbox", "regex", "reject", "variables"];
    
    if anyof(
        header :contains "List-Subscribe" "groups.google.com",
        header :matches "X-Google-Group-Id" "*"
       ) {
    	if header :matches "Subject" "*" {
    		set "subject" "${1}";
    	} else {
    		set "subject" "";
    	}
    	deleteheader "Subject";
    	addheader :last "Subject" "[Google-Groups-Spam] ${subject}";
    
    	fileinto "Junk";
    }
    




  • Generally yes, but I wasn’t talking to them. If you switch operating systems, you need to do some work to learn how they work. Yes, Linix could be way more „noob friendly“. Yes, even distributions that make this process as painless as possible (e.g. Fedora that automates everything with akmods) require you to load the generated MOK into your UEFI manually and that looks very scary (by design - it’s usually only a good idea to load a MOK if you know what you’re doing and why as it can break the whole trust concept of secure boot).

    The main problem with Linux for mass adoption is IMHO that there’s still many cases that require you to leverage the terminal or edit config files. And to some degree that there isn’t „one official way“ of doing or customizing things. Yes it’s cool to be able to do all those things and to have the freedom, but I also respect people that just want it to work and not need to tinker everywhere.


  • I feel there’s a trust problem here. I’m no Windows dev, so I don’t know all the details, but since MS enforces secure boot, they have to play by the rules: Only trusted code can be executed with very high (kernel level) privileges. That’s one of the reasons why they want to enforce signed binaries. Especially for drivers and other stuff.

    On Windows that means only entities that MS trusts are allowed to execute high privileged code. Otherwise you wouldn’t get your binaries signed by MS (or co-signed, or white-listed or whatever aproach they take in this scenario) and without signature, no execution. You need to trust MS, but you need to trust them anyways, as they control the chain of trust on boot and also create the very kernel you’re running on. If they wanted to cheat you, it’s be easy for them.

    On Linux it’s a bit different. Linux has the aproach that any user with root privileges is trustworthy. That’s good for me, as I get a say on what runs on my hardware and how it runs. But for the anti cheat vendor that’s now a huge problem, because a random person is now the one controlling the kernel, its integrity and the chain of trust on boot. Worse: It’s usually the very person they’re trying to observe if they’re cheating. But how do you do this, if they (theoretically) have full control over the kernel and can run arbitrary kernel modules?

    Now, I’m not saying that there’s no trust in the Linux kernel and Windows were more secure - just that there are completely different assumptions about trust and trust boundaries that may lead to severe headaches for the anti cheat vendors.


  • How does DKMS and such break secure boot? If you want to load (custom) kernel modules, just generate a key pair, sign the module yourself, import your MOK into your UEFI (once, assuming you use the same key for all your modules and also keep a backup of your reinstall your system) and secure boot will let you do that.

    I’m running current NVIDIA drivers on Linux and that’s basically the setup to use them- and since that is already set up, i’d not even need to to anything specific to get it working for other things.

    Note: I do not endorse kernel level anti cheat and would never load such a module, but the infrastructure for it is already there and can be used with secure boot…