<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet href="/feeds.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:base="https://chameth.com/">
    <title>Chameth.com - posts like g15-ram-upgrade, offline-gnupg-master-yubikey-subkeys but not debugging-beyond-the-debugger, why-you-should-be-using-https</title>
    <subtitle>Personal homepage of Chris Smith</subtitle>
    <link href="https://chameth.com/feeds/posts/like/g15-ram-upgrade,offline-gnupg-master-yubikey-subkeys/unlike/debugging-beyond-the-debugger,why-you-should-be-using-https/" rel="self"/>
    <link href="https://chameth.com/"/>
    <icon>https://chameth.com/favicon.png</icon>
    <updated>2023-07-29T00:00:00Z</updated>
    <id>https://chameth.com/</id>
    <author>
        <name>Chris Smith</name>
    </author>
    <entry>
        <title>Upgrading the RAM in a Dell G15 laptop</title>
        <link href="https://chameth.com/g15-ram-upgrade/"/>
        <updated>2023-07-29T00:00:00Z</updated>
        <id>https://chameth.com/g15-ram-upgrade/</id>
        <content xml:lang="en" type="html">&lt;figure class=&#34;image left&#34;&gt;
  &lt;picture&gt;
      &lt;source srcset=&#34;https://chameth.com/g15-ram-upgrade/g15.avif&#34; type=&#34;image/avif&#34;/&gt;
      &lt;source srcset=&#34;https://chameth.com/g15-ram-upgrade/g15.webp&#34; type=&#34;image/webp&#34;/&gt;
      &lt;img src=&#34;https://chameth.com/g15-ram-upgrade/g15.png&#34; alt=&#34;An open Dell G15 laptop&#34; loading=&#34;lazy&#34; width=&#34;580&#34; height=&#34;402&#34;/&gt;
  &lt;/picture&gt;
  &lt;figcaption&gt;&lt;p&gt;The Dell G15&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;I currently use a Dell G15 laptop for work. It has served me well for a little
over a year, but recently it has been struggling a little with my day-to-day
workload. It came with 32GB of RAM — the highest possible specification at the
time&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a class=&#34;footnote-ref&#34; href=&#34;#fn:1&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; — but that is apparently no longer enough for me.&lt;/p&gt;
&lt;p&gt;For a recent project, I was working on a Rust library used in an Android app.
That meant running the usual glut of Android tools (Android Studio, an emulator
and at least one Gradle daemon) alongside a normal IDE (IntelliJ IDEA). Throw
in a web browser and a couple of electron apps, and I often managed to
use all 32GB.&lt;/p&gt;
&lt;p&gt;When you start swapping memory out to an encrypted disk — even an SSD — it
doesn’t make for great performance. At first, I tried to work around this
by enabling the Linux out-of-memory (OOM) killer, but it turns out that it’s not
too good with Electron apps: it will kill the large browser process, but then
the small Electron wrapper will just respawn it.&lt;/p&gt;
&lt;!--more--&gt;
&lt;h3 id=&#34;can-it-be-upgraded-or-not&#34;&gt;Can it be upgraded or not?&lt;/h3&gt;
&lt;p&gt;The obvious solution to not having enough RAM is to add more RAM. A quick look
in the manual showed this might not be possible, though. The manual includes
the following “Memory specifications” table:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;th&gt;Values&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Memory slots&lt;/td&gt;
&lt;td&gt;Two SODIMM slots&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Memory type&lt;/td&gt;
&lt;td&gt;DDR5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Memory speed&lt;/td&gt;
&lt;td&gt;4800&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Maximum memory configuration&lt;/td&gt;
&lt;td&gt;32GB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Minimum memory configuration&lt;/td&gt;
&lt;td&gt;8GB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Memory size per slot&lt;/td&gt;
&lt;td&gt;8GB or 16GB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Memory configurations supported&lt;/td&gt;
&lt;td&gt;&lt;ul&gt;&lt;li&gt;8 GB, 1 x 8 GB, DDR5, 4800 MHz&lt;/li&gt;&lt;li&gt;16 GB, 1 x 16 GB, DDR5, 4800 MHz&lt;/li&gt;&lt;li&gt;16 GB, 2 x 8 GB, DDR5, 4800 MHz, dual-channel&lt;/li&gt;&lt;li&gt;32 GB, 2 x 16 GB, DDR5, 4800 MHz, dual-channel&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;That unambiguously says that an upgrade from 32GB is not possible. I gave up.&lt;/p&gt;
&lt;p&gt;Later though, I was complaining about memory issues to a friend, and he pointed
out a Dell forum thread where a couple of people claim to have successfully
installed dual-channel 32GB modules. Since the alternative was getting an
entire new PC after only a year, I decided to give it a go.&lt;/p&gt;
&lt;h3 id=&#34;the-upgrade-attempt&#34;&gt;The upgrade attempt&lt;/h3&gt;
&lt;p&gt;I ordered a pair of Crucial 32GB DDR5-4800 SODIMMs, and after they turned up
dismantled the laptop. The G15 comes apart pretty normally: there are uncovered
screws on the bottom holding the lower part of the case on. With those
removed and some gentle prying, it pops off, and you get access to the battery,
GPU and motherboard.&lt;/p&gt;
&lt;p&gt;The first thing I saw was this:&lt;/p&gt;
&lt;figure class=&#34;image full&#34;&gt;
  &lt;picture&gt;
      &lt;source srcset=&#34;https://chameth.com/g15-ram-upgrade/motherboard.avif&#34; type=&#34;image/avif&#34;/&gt;
      &lt;source srcset=&#34;https://chameth.com/g15-ram-upgrade/motherboard.webp&#34; type=&#34;image/webp&#34;/&gt;
      &lt;img src=&#34;https://chameth.com/g15-ram-upgrade/motherboard.jpg&#34; alt=&#34;The G15 motherboard, with a large &amp;#34;DDR5 8G/16G Only&amp;#34; label, and a smaller &amp;#34;DIMM B DDR5 8G/16G&amp;#34; label next to a SODIMM slot&#34; loading=&#34;lazy&#34; width=&#34;1536&#34; height=&#34;1300&#34;/&gt;
  &lt;/picture&gt;
  &lt;figcaption&gt;&lt;p&gt;The G15 motherboard adamantly proclaiming that it doesn’t want 32GB SODIMMs&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Not one but two labels that indicate it will only accept 8GB or 16GB modules.
Oh well, what’s the worst that can happen?&lt;/p&gt;
&lt;h3 id=&#34;oops&#34;&gt;Oops?&lt;/h3&gt;
&lt;p&gt;I dutifully installed the new modules, reconnected the battery and put the
case back together. I pressed the power button, and… nothing. None of the
usual garish lights that immediately come on, no screen output, just a dead
laptop. After reading some more of the user manual, I found that there is a tiny
status LED on the side next to the ethernet port. Forcing the laptop to power
off and back on again, the status LED blinked a distress code at me: 2 amber
blinks, 4 white blinks. The manual says that is — unsurprisingly — a memory
fault.&lt;/p&gt;
&lt;p&gt;I figured at this point that the manual and labels on the motherboard were
probably right. I took the laptop apart again, reinstalled the original 2x16GB
modules, reassembled it, and pressed the power button. It didn’t boot. I don’t
spend a lot of time fiddling inside computers, but I’ve done it enough that
I’m reasonably confident I can’t entirely break a computer while swapping some
RAM modules. I took to Googling&lt;sup id=&#34;fnref:2&#34;&gt;&lt;a class=&#34;footnote-ref&#34; href=&#34;#fn:2&#34; role=&#34;doc-noteref&#34;&gt;2&lt;/a&gt;&lt;/sup&gt;, and found an interesting article that said
Dell laptops don’t like to boot after RAM changes unless you clear the CMOS by
popping out the battery for 15 minutes.&lt;/p&gt;
&lt;p&gt;I opened the laptop up, and looked around for the CMOS battery. There wasn’t
one. Turns out they don’t exist any more. I left the main battery disconnected
for a while to see if it would help, and it didn’t.&lt;/p&gt;
&lt;h3 id=&#34;unexpected-success&#34;&gt;Unexpected success&lt;/h3&gt;
&lt;p&gt;I started to get worried: if I couldn’t fix this, I wouldn’t be able to
work until I got a new PC, and that wasn’t really in my budget at the minute.
I sat reading old forum threads and help guides&lt;sup id=&#34;fnref:3&#34;&gt;&lt;a class=&#34;footnote-ref&#34; href=&#34;#fn:3&#34; role=&#34;doc-noteref&#34;&gt;3&lt;/a&gt;&lt;/sup&gt;, none of which were actually
useful. Out of nowhere, though, the laptop booted up.&lt;/p&gt;
&lt;p&gt;Naturally, I immediately shut the laptop down again, opened it up, and switched
back to the new RAM modules. Then I turned it on again and sat waiting. After
about 15 minutes of it looking totally dead, it turned on and showed a BIOS
warning about the hardware configuration being changed. It then booted perfectly
normally, and all 64GB of RAM was visible and usable.&lt;/p&gt;
&lt;p&gt;My theory is that the forum threads were right: Dell laptops are funny about
RAM upgrades. But somehow in removing the physical CMOS battery, they’ve kept
the same “you have to wait 15 minutes” behaviour just without any indication
that’s what’s happening. Regardless, I now have enough RAM even for the
greediest of IDEs and Electron apps.&lt;/p&gt;
&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;
&lt;hr/&gt;
&lt;ol&gt;
&lt;li id=&#34;fn:1&#34;&gt;
&lt;p&gt;Bizarrely, the maximum spec has &lt;em&gt;decreased&lt;/em&gt; to 16GB since then. &lt;a class=&#34;footnote-backref&#34; href=&#34;#fnref:1&#34; role=&#34;doc-backlink&#34;&gt;↩︎&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:2&#34;&gt;
&lt;p&gt;In the generic sense. I use &lt;a href=&#34;https://kagi.com/&#34;&gt;Kagi&lt;/a&gt; these days. &lt;a class=&#34;footnote-backref&#34; href=&#34;#fnref:2&#34; role=&#34;doc-backlink&#34;&gt;↩︎&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:3&#34;&gt;
&lt;p&gt;On my phone because, y’know, the laptop was busted. &lt;a class=&#34;footnote-backref&#34; href=&#34;#fnref:3&#34; role=&#34;doc-backlink&#34;&gt;↩︎&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
</content>
    </entry>
    <entry>
        <title>Creating an offline GnuPG master key with Yubikey-stored subkeys</title>
        <link href="https://chameth.com/offline-gnupg-master-yubikey-subkeys/"/>
        <updated>2016-08-11T00:00:00Z</updated>
        <id>https://chameth.com/offline-gnupg-master-yubikey-subkeys/</id>
        <content xml:lang="en" type="html">&lt;figure class=&#34;image right&#34;&gt;
  &lt;picture&gt;
      &lt;source srcset=&#34;https://chameth.com/offline-gnupg-master-yubikey-subkeys/keys.avif&#34; type=&#34;image/avif&#34;/&gt;
      &lt;source srcset=&#34;https://chameth.com/offline-gnupg-master-yubikey-subkeys/keys.webp&#34; type=&#34;image/webp&#34;/&gt;
      &lt;img src=&#34;https://chameth.com/offline-gnupg-master-yubikey-subkeys/keys.png&#34; alt=&#34;A pair of Yubikeys&#34; loading=&#34;lazy&#34; width=&#34;250&#34; height=&#34;250&#34;/&gt;
  &lt;/picture&gt;
  &lt;figcaption&gt;&lt;p&gt;A pair of Yubikeys&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;I recently noticed that I’d accidentally lost my previous GPG private key — whoops. It was on
a drive that I’d since formatted and used for a fair amount of time, so there’s no hope of
getting it back (but, on the plus side, there’s also no risk of anyone else getting their hands on
it). I could have created a new one in a few seconds and been done with it, but I decided to treat
it as an exercise in doing things properly.&lt;/p&gt;
&lt;h3 id=&#34;background-gpg-yubikey&#34;&gt;Background: GPG? Yubikey?&lt;/h3&gt;
&lt;p&gt;GPG or GnuPG is short for &lt;a href=&#34;https://www.gnupg.org/&#34;&gt;Gnu Privacy Guard&lt;/a&gt;, which is a suite of
applications that provide cryptographic privacy and authentication functionality. At a basic level,
it works in a similar way to HTTPS certificates: each user has a public key which is shared widely,
and a private key that is unique to them. You can use someone else’s public key to encrypt messages
so only they can see them, and use your own private key to sign content so that others can verify
it came from you.&lt;/p&gt;
&lt;p&gt;A &lt;a href=&#34;https://www.yubico.com/faq/yubikey/&#34;&gt;Yubikey&lt;/a&gt; is a small hardware device that offers two-factor
authentication. Most Yubikey models also act as smartcards and allow you to store OpenPGP
credentials on them.&lt;/p&gt;
&lt;!--more--&gt;
&lt;h3 id=&#34;introducing-subkeys&#34;&gt;Introducing subkeys&lt;/h3&gt;
&lt;p&gt;GnuPG supports subkeys, which provide fairly significant security advantages. Instead of just having
a single public and private key, you have a master pair and then any number of subkey pairs. The
subkeys are automatically associated with the master key, but they can be revoked independently.&lt;/p&gt;
&lt;p&gt;Having a master key fall into the wrong hands is a problem — you have to revoke the whole
thing (assuming you have access to a revocation certificate) and start again, convincing everyone
else that your new key is the “real” you. With subkeys, you can issue a revocation signed with your
master key and then sign some new subkeys. There’s no loss of trust, and as long as people refresh
your key from a keyserver, everything carries on as normal.&lt;/p&gt;
&lt;p&gt;The other advantage to using subkeys is that you can keep the master key elsewhere. It doesn’t
need to be routinely accessible, and using it doesn’t require access to the Internet. The master
key is kept offline, significantly reducing the risk of anything bad happening to it.&lt;/p&gt;
&lt;h3 id=&#34;setting-up-a-secure-environment&#34;&gt;Setting up a secure environment&lt;/h3&gt;
&lt;p&gt;My main desktop runs Windows, and most of my other devices are work ones which come with automatic
backups and network mounts that I don’t fully grok. Neither of those is a particularly good option
if I want to do something security sensitive.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://tails.boum.org/&#34;&gt;Tails&lt;/a&gt; is the defacto choice for a secure, live linux system, so I went
through their installation process and eventually ended up with a USB drive that can boot into
Tails. The installation process from Windows is slightly convoluted, as it involves creating a
bootable Tails image, then booting to that and using the Tails installer to create the real image
on a different drive. If you’re starting on a Linux box, you can just use the Tails installer
directly instead of doing the two-drive shuffle.&lt;/p&gt;
&lt;p&gt;Just to be completely paranoid, I disconnected my PC from the network before booting Tails. This
is known as &lt;a href=&#34;https://en.wikipedia.org/wiki/Air_gap_%28networking%29&#34;&gt;air-gapping&lt;/a&gt;, and is done to
eliminate the possibility of a remote attacker doing something to your system. Ideally the machine
never would have been connected to the network, but I didn’t happen to have an unused machine
laying around.&lt;/p&gt;
&lt;p&gt;The final thing I needed was a secure place to store my master key. I opted for an
&lt;a href=&#34;http://www.ironkey.com/en-US/&#34;&gt;IronKey&lt;/a&gt; — a hardware-encrypted USB drive that self-destructs
if there are too many unsuccessful attempts to access it. It works out-of-the-box on both Windows
and Linux, presenting a small unencrypted drive with software to run to interact with the secure
partition.&lt;/p&gt;
&lt;h3 id=&#34;creating-the-keys&#34;&gt;Creating the keys&lt;/h3&gt;
&lt;p&gt;Now I had a nice over-the-top setup it was time to actually the keys. There is &lt;a href=&#34;https://blog.josefsson.org/2014/06/23/offline-gnupg-master-key-and-subkeys-on-yubikey-neo-smartcard/&#34;&gt;an excellent
guide by Simon Josefsson&lt;/a&gt;
that walks through the entire process of creating the master key, creating three subkeys, and
then transferring them to a Yubikey.&lt;/p&gt;
&lt;p&gt;The only point where I had to deviate from Simon’s guide was setting the machine up to work with
the Yubikeys. I was setting up two keys (a nano and a neo), and one just worked out of the box
with the version of &lt;code&gt;libykpers-1-1&lt;/code&gt; that was in Tails’ apt repository. The other needed a slightly
newer version but that was also available in apt and can be selected by specifying the version
manually as pointed out in &lt;a href=&#34;https://github.com/freedomofpress/securedrop/issues/1035#issuecomment-140172267&#34;&gt;this GitHub issue&lt;/a&gt;.
The version numbers have since changed, but &lt;code&gt;apt-policy&lt;/code&gt; makes it easy to figure out what’s needed.
As I was using an air-gapped system this process was a bit more complicated than it sounds,
involving several USB drive transfers.&lt;/p&gt;
&lt;p&gt;After finishing the guide, I had my master key and a pre-generated revocation certificate stored
securely on my IronKey, and the three subkeys stored on each Yubikey. Time to go back to Windows.&lt;/p&gt;
&lt;h3 id=&#34;gpg-windows-and-ssh&#34;&gt;GPG, Windows and SSH&lt;/h3&gt;
&lt;p&gt;Now with the IronKey disconnected and the master key out of harms way, it’s time to go back to
Windows. I downloaded the &lt;a href=&#34;https://www.gnupg.org/download/&#34;&gt;GnuPG Modern&lt;/a&gt; distribution and
followed the instructions at the end of Simon’s guide to import my public key and make GPG aware
of the subkeys on the Yubikey. After that &lt;a href=&#34;https://www.enigmail.net/index.php/en/&#34;&gt;Enigmail&lt;/a&gt;
was able to sign and encrypt e-mail in Thunderbird.&lt;/p&gt;
&lt;figure class=&#34;image left&#34;&gt;
  &lt;picture&gt;
      &lt;source srcset=&#34;https://chameth.com/offline-gnupg-master-yubikey-subkeys/wisdom_of_the_ancients.avif&#34; type=&#34;image/avif&#34;/&gt;
      &lt;source srcset=&#34;https://chameth.com/offline-gnupg-master-yubikey-subkeys/wisdom_of_the_ancients.webp&#34; type=&#34;image/webp&#34;/&gt;
      &lt;img src=&#34;https://chameth.com/offline-gnupg-master-yubikey-subkeys/wisdom_of_the_ancients.png&#34; alt=&#34;XKCD: Wisdom of the Ancients&#34; loading=&#34;lazy&#34; width=&#34;485&#34; height=&#34;270&#34;/&gt;
  &lt;/picture&gt;
  &lt;figcaption&gt;&lt;p&gt;&lt;a href=&#34;https://xkcd.com/979/&#34;&gt;XKCD #979: Wisdom of the ancients&lt;/a&gt;&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Next up, I enabled PuTTy support and started the GPG agent, as documented over on
&lt;a href=&#34;https://developers.yubico.com/PGP/SSH_authentication/Windows.html&#34;&gt;Yubico’s site&lt;/a&gt;. This allows
you to use the authentication GPG key to authenticate SSH sessions from PuTTy. To find the
SSH key you need to add to &lt;code&gt;.authorized_keys&lt;/code&gt;, simply run &lt;code&gt;gpg --export-ssh-key&lt;/code&gt;. At first I
could SSH into a host but not use agent forwarding. After lots of unsuccessful Googling, I realised
that GPG couldn’t access the key anymore locally. Another quick search and I found a
&lt;a href=&#34;http://forum.yubico.com/viewtopic.php?f=35&amp;amp;t=2231&#34;&gt;forum thread&lt;/a&gt; where someone had the same
issue and found it was a problem with exclusive access to the card. They even passed on their
wisdom and updated the thread with a solution, which got everything working for me.&lt;/p&gt;
&lt;h3 id=&#34;vmware&#34;&gt;VMWare&lt;/h3&gt;
&lt;p&gt;I have a Ubuntu image running inside VMWare on my desktop that I use for most development
activities. I’m unlikely to want to sign e-mail, but I probably want to sign commits (especially
now that &lt;a href=&#34;https://github.com/blog/2144-gpg-signature-verification&#34;&gt;GitHub exposes verified signatures&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;To do that I need to pass the Yubikey through to the virtual machine. In its default configuration,
VMWare recognises the Yubikey device but doesn’t pass it through correctly. You need to configure it
to &lt;a href=&#34;http://www.timothysalmon.com/2014/12/vmware-workstation-connect-yubikey-to.html&#34;&gt;allow HIDs&lt;/a&gt;,
after which &lt;code&gt;gpg --card-status&lt;/code&gt; starts working from the VM.&lt;/p&gt;
&lt;p&gt;Unfortunately passing through the device makes it exclusively available to the VM so the host OS
can no longer use it. As I have two Yubikeys, I just configured VMWare to ignore the nano key that’s
always plugged in, and pass through the neo when I plug that in. While swapping the configuration
around, I found out that GPG remembers the ID of the smartcard that store credentials - if you
swap the two keys with identical subkeys it demands the other one is reinserted. You can get rid of
the references to the previous card using &lt;code&gt;gpg --delete-secret-keys&lt;/code&gt;.&lt;/p&gt;
&lt;h3 id=&#34;in-conclusion&#34;&gt;In conclusion…&lt;/h3&gt;
&lt;p&gt;… I have a &lt;a href=&#34;https://chameth.com/16402FE2.txt&#34;&gt;new PGP key&lt;/a&gt; you can use to verify things I sign or encrypt
messages to me.&lt;/p&gt;
</content>
    </entry>
</feed>
