Skip to content

Comment on Bootimus – A Self-Contained PXE and HTTP Boot Serverparent

Comments

There is a note on there around AI coding which gives a little more hope. But what i would expect from such a component is also a clear indication of how its security is being vetter, tested and attempted to be assured.

When using such a server, its of critical importance its secure. If someone can enter it, they can change your images, knock over a machine and get it to boot a rogue image etc.

Id be interested what thread models are taken into account. If there is any fuzzing.

Perhaps a clear list of all the third party packages it pulls in and assessment of those packages.

It sounds like a lot but actually AI can help set up a lot of tooling around this stuff to make it more managable to do a lot of thorough testing / vetting of things.

I do think its also interesting project, and ofc it might be somehting that matures over time in this regard. (i am super biassed about security also as its my domain and i've litterally seen colleagues root servers which hosted images for entire infras of companies. thats a scary vector. if you can tamper with 1 PXE boot you can overwrite firmware.

(this is not saying anything about secure boot ofc, my experiences with PXE predate that being actively deployed)

Author here - it's a freaking internal only tool, if you are exposing a PXE server to the outside world you get everything you deserve.

What you are describing can happen with any tool, iVentoy literally injects code into your images without you knowing as it's closed source. NetbootXYZ have crazy CI Pipelines and ansible to make it work.

I tried to make it as single binary, open and single shot as possible.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.