news.volyx.in

Ask HN: How do you trust that your personal machine is not compromised?

541 points by coderatlarge · 1328 days ago · 448 comments on HN

Article summary

The article asks how one can trust that their personal machine is not compromised by malware or malicious third parties at any level, including BIOS, firmware, OS, or apps. The question implies a desire to ensure the security and privacy of one's device. Compromise could occur through various means, including installation of malware or unauthorized access. Ensuring the security of a personal machine is a complex task.

Main themes

  • Device Security
  • Malware and Compromise
  • Encryption and Privacy
  • Risk Assessment and Precautions
  • Security Habits and Best Practices
  • Advanced Threats and Uncertainty

What commenters say

  • One should assume all devices are compromised and take precautions accordingly, such as using encryption and limiting attack surfaces.
  • It is possible to communicate securely even from a compromised device, but this requires careful measures.
  • Assuming a device is compromised does not necessarily mean one cannot use encryption, but rather that additional precautions are needed.
  • Some argue that it is not practical or necessary to constantly check for compromise, and that a reasonable level of precaution is sufficient.
  • Others believe that even with precautions, it is impossible to be certain that a device is not compromised, especially in the face of advanced threats.
  • The idea of assuming compromise can be helpful in guiding security practices, such as not allowing remote access and using strong authentication.
  • Regular security habits, such as locking screens and using password managers, are seen as essential by some, while others view them as low-effort tasks that are easy to implement.
  • There is disagreement on whether it is worthwhile to prioritize security measures that may be seen as inconvenient or unnecessary, depending on the individual's risk assessment.