3 ms·
Appreciate the fully secure boot process, even if the Intel situation isn't fully secure. Wish I had an external uC with burned-in firmware on my machine that I
by saynsedit 10y ago
Appreciate the fully secure boot process, even if the Intel situation isn't fully secure. Wish I had an external uC with burned-in firmware on my machine that I trusted to verify my BIOS firmware and orchestrate the boot process.
- talltower 10y agoThanks. We agree with your statement fully. We are raising the threshold of entry to your personal data substantially, but we are still far from perfection. We did a number of steps up in the security ladder. We are also taking steps to minimize ME abilities in ORWL. Our long term plan is to limit ME capabilities using the BIOS configuration. We just released the SOW of the 1st BIOS with Eltan on the WiKi. https://www.orwl.org/wiki/index.php?title=File%3ASowDESIGN-SHIFTORWLPUBLIC20160902.pdf https://www.orwl.org/wiki/index.php?title=File%3ASowDESIGN-S... We are planning to investigate how to further limit ME capabilities with Eltan and we will update the SOW as we make progress. We also believe that the current secure micro controller implementation severely limit the ME capability through power management and the SSD key management.