Page 1 of 1

Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would ver

Posted: 2022-08-27 17:00
by Udaba
Device Security comes with Gnome 43. Thats an awesome feature.
It would very helpful if it was a guide helping you secure the system.
Is there any out there?Post them here and let create a guide.

1. Level 1

* Intel Managemenent Engine Version

* UEFI Platform Key
* TPM v2.0
*You can enable it on your BIOS on Boot settings.*
* Firmware BIOS Region
* Firmware Writ Protection Lock
* Platform Debugging
* Intel Management Engine Manufacturing Mode
* UEFI Secure Boot
* Firmware Write Protection
* Intel Management Engine Override
* TPM Platform Configuration
2. Level 2
* Intel BootGuard Fuse
* Intel BootGuard Verified Boot
* Intel BootGuard Protected
* Intel BootGuard
* TPM Reconstruction
* IOMMU Protection
* Platform Debugging
3. Level 3
* Suspend To RAM
* Intel BootGuard Error Policy
* Pre-boot DMA Protection
* Intel CET Enabled
* Suspend To Idle
* Encrypted RAM
* Intel SMAP

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

Posted: 2022-08-27 23:53
by sunrat
Udaba wrote: 2022-08-27 17:00 It would very helpful if it was a guide helping you secure the system.
Is there any out there?
I'm sure there a many on the internet.

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

Posted: 2022-08-28 08:28
by Head_on_a_Stick
You don't need GNOME to tell you if SecureBoot is enabled:

Code: Select all

# bootctl status
Or

Code: Select all

mokutil --sb-state

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

Posted: 2022-08-28 13:49
by Udaba
Im totally noob on this. Im looking for ways to make them secure and create a guide for newcomers like me.

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

Posted: 2022-08-28 15:05
by Head_on_a_Stick
The stable release should use SecureBoot automatically, no need for a guide. EDIT: newer machines may need 3rd party certificates authorised from the firmware ("BIOS") menus.

Version 43 of GNOME might make it into Debian 12 when it is released so you should see the feature there, hopefully.

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

Posted: 2022-09-06 23:41
by Udaba
I really hope so. Seems a very nice feature to have. Im really noob on this so thats why i created this post.
Im actually using testing thats why i saw it.

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

Posted: 2023-04-22 16:23
by Uptorn
If the new Gnome security feature does anything other than
!!! Warning !!! Intel hardware rootkit IME/ME detected on your system! Replace your hardware as soon as possible with a freedom respecting solution. Recommendations:
<list of liberated hardware>
then I suggest its output can be safely ignored.

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

Posted: 2023-04-22 19:59
by fabien
Uptorn wrote: 2023-04-22 16:23
!!! Warning !!! Intel hardware rootkit IME/ME detected on your system! Replace your hardware as soon as possible with a freedom respecting solution. Recommendations:
<list of liberated hardware>
Worrisome, but what is your hardware?
https://en.wikipedia.org/wiki/Intel_Management_Engine
Intel's main competitor AMD has incorporated the equivalent AMD Secure Technology (formally called Platform Security Processor) in virtually all of its post-2013 CPUs.

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

Posted: 2023-10-05 04:18
by Uptorn
fabien wrote: 2023-04-22 19:59 Worrisome, but what is your hardware?
Neither of those things :cool:

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

Posted: 2023-10-28 10:48
by fabien
Uptorn wrote: 2023-10-05 04:18Neither of those things :cool:
I'm happy for you. So, what is the
Uptorn wrote: 2023-04-22 16:23 <list of liberated hardware>
:?:

Re: Gnome Feature / Device Security feature GuideDevice Security comes with Gnome 43. Thats an awesome feature. It would

Posted: 2023-10-28 14:23
by Uptorn
fabien wrote: 2023-10-28 10:48 :?:
It was just a stand-in to illustrate my point. But if I had to begin to construct such a list it might include vendors like Purism, System76, Technoethical, SciFive, Raptor Computing Systems and MiniFree.