Scheduled Maintenance: We are aware of an issue with Google, AOL, and Yahoo services as email providers which are blocking new registrations. We are trying to fix the issue and we have several internal and external support tickets in process to resolve the issue. Please see: viewtopic.php?t=158230

 

 

 

Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would ver

Here you can discuss every aspect of Debian. Note: not for support requests!
Post Reply
Message
Author
Udaba
Posts: 80
Joined: 2019-03-18 00:35
Has thanked: 4 times

Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would ver

#1 Post by Udaba »

Device Security comes with Gnome 43. Thats an awesome feature.
It would very helpful if it was a guide helping you secure the system.
Is there any out there?Post them here and let create a guide.

1. Level 1

* Intel Managemenent Engine Version

* UEFI Platform Key
* TPM v2.0
*You can enable it on your BIOS on Boot settings.*
* Firmware BIOS Region
* Firmware Writ Protection Lock
* Platform Debugging
* Intel Management Engine Manufacturing Mode
* UEFI Secure Boot
* Firmware Write Protection
* Intel Management Engine Override
* TPM Platform Configuration
2. Level 2
* Intel BootGuard Fuse
* Intel BootGuard Verified Boot
* Intel BootGuard Protected
* Intel BootGuard
* TPM Reconstruction
* IOMMU Protection
* Platform Debugging
3. Level 3
* Suspend To RAM
* Intel BootGuard Error Policy
* Pre-boot DMA Protection
* Intel CET Enabled
* Suspend To Idle
* Encrypted RAM
* Intel SMAP

User avatar
sunrat
Administrator
Administrator
Posts: 6511
Joined: 2006-08-29 09:12
Location: Melbourne, Australia
Has thanked: 119 times
Been thanked: 489 times

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

#2 Post by sunrat »

Udaba wrote: 2022-08-27 17:00 It would very helpful if it was a guide helping you secure the system.
Is there any out there?
I'm sure there a many on the internet.
“ computer users can be divided into 2 categories:
Those who have lost data
...and those who have not lost data YET ”
Remember to BACKUP!

User avatar
Head_on_a_Stick
Posts: 14114
Joined: 2014-06-01 17:46
Location: London, England
Has thanked: 81 times
Been thanked: 133 times

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

#3 Post by Head_on_a_Stick »

You don't need GNOME to tell you if SecureBoot is enabled:

Code: Select all

# bootctl status
Or

Code: Select all

mokutil --sb-state
deadbang

Udaba
Posts: 80
Joined: 2019-03-18 00:35
Has thanked: 4 times

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

#4 Post by Udaba »

Im totally noob on this. Im looking for ways to make them secure and create a guide for newcomers like me.

User avatar
Head_on_a_Stick
Posts: 14114
Joined: 2014-06-01 17:46
Location: London, England
Has thanked: 81 times
Been thanked: 133 times

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

#5 Post by Head_on_a_Stick »

The stable release should use SecureBoot automatically, no need for a guide. EDIT: newer machines may need 3rd party certificates authorised from the firmware ("BIOS") menus.

Version 43 of GNOME might make it into Debian 12 when it is released so you should see the feature there, hopefully.
deadbang

Udaba
Posts: 80
Joined: 2019-03-18 00:35
Has thanked: 4 times

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

#6 Post by Udaba »

I really hope so. Seems a very nice feature to have. Im really noob on this so thats why i created this post.
Im actually using testing thats why i saw it.

User avatar
Uptorn
Posts: 244
Joined: 2022-01-22 01:07
Has thanked: 210 times
Been thanked: 56 times

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

#7 Post by Uptorn »

If the new Gnome security feature does anything other than
!!! Warning !!! Intel hardware rootkit IME/ME detected on your system! Replace your hardware as soon as possible with a freedom respecting solution. Recommendations:
<list of liberated hardware>
then I suggest its output can be safely ignored.

User avatar
fabien
Forum Helper
Forum Helper
Posts: 688
Joined: 2019-12-03 12:51
Location: Anarres (Toulouse, France actually)
Has thanked: 62 times
Been thanked: 161 times

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

#8 Post by fabien »

Uptorn wrote: 2023-04-22 16:23
!!! Warning !!! Intel hardware rootkit IME/ME detected on your system! Replace your hardware as soon as possible with a freedom respecting solution. Recommendations:
<list of liberated hardware>
Worrisome, but what is your hardware?
https://en.wikipedia.org/wiki/Intel_Management_Engine
Intel's main competitor AMD has incorporated the equivalent AMD Secure Technology (formally called Platform Security Processor) in virtually all of its post-2013 CPUs.

User avatar
Uptorn
Posts: 244
Joined: 2022-01-22 01:07
Has thanked: 210 times
Been thanked: 56 times

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

#9 Post by Uptorn »

fabien wrote: 2023-04-22 19:59 Worrisome, but what is your hardware?
Neither of those things :cool:

User avatar
fabien
Forum Helper
Forum Helper
Posts: 688
Joined: 2019-12-03 12:51
Location: Anarres (Toulouse, France actually)
Has thanked: 62 times
Been thanked: 161 times

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

#10 Post by fabien »

Uptorn wrote: 2023-10-05 04:18Neither of those things :cool:
I'm happy for you. So, what is the
Uptorn wrote: 2023-04-22 16:23 <list of liberated hardware>
:?:

User avatar
Uptorn
Posts: 244
Joined: 2022-01-22 01:07
Has thanked: 210 times
Been thanked: 56 times

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

#11 Post by Uptorn »

fabien wrote: 2023-10-28 10:48 :?:
It was just a stand-in to illustrate my point. But if I had to begin to construct such a list it might include vendors like Purism, System76, Technoethical, SciFive, Raptor Computing Systems and MiniFree.

Post Reply