Try not to get duped by projects pushing an ARM SoC and other proprietary hardware components as open hardware without proprietary firmware. There are several projects very deliberately misrepresenting this, misleading users and putting them at risk by not providing the updates.
-
-
Prikaži ovu nit
-
Full security updates covering all components are incredibly important. Being able to update firmware/microcode rather than replacing hardware over and over again is not a negative. Verified boot, keystore HSMs and other hardware-based security features are also important things.
Prikaži ovu nit -
It's also important to note that hardware isolation is orthogonal to whether a component is implemented on the same die. In fact, in many cases, components on the SoC chip have better isolation than those outside it due to lack of security work across organizational boundaries.
Prikaži ovu nit -
Privacy and security have been hijacked for marketing by not just companies but also open source projects. You cannot believe what you read on these topics from most companies, projects or the media. The industry is full of scammers, dishonesty and ignorance. It's sad all around.
Prikaži ovu nit -
I find it extremely frustrating. On a day to day basis, I encounter an endless torrent of misinformation and bogus marketing claims. I expect nothing less from tech giants and security companies but it's really sad seeing the same from open source projects and non-profit orgs.
Prikaži ovu nit -
Privacy /security are effectively just a marketing approach at this point. Substance doesn't matter. Projects focused on improving privacy and security get pushed out by those pretending to do it. Proprietary hardware falsely presented as open gets funding over open hardware too.
Prikaži ovu nit
Kraj razgovora
Novi razgovor -
-
-
Then close off the attack surface to access these from untrusted domains. Installing new black boxes is not security hygiene.
-
There's a lot of work by others on improving isolation for these components and reducing exposed attack surface. I'm not particularly focused on security in this thread but rather frustration with projects falsely pretending to be open hardware or provide better privacy/security.
- Još 27 drugih odgovora
Novi razgovor -
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.