4 ms·
The same way secure-boot provides protection against hardware modification / evil maid type attacks in CPUs today: by verifying the integrity of the code that's
by rjst01 8y ago
The same way secure-boot provides protection against hardware modification / evil maid type attacks in CPUs today: by verifying the integrity of the code that's about to be booted before the CPU boots it.
It would significantly raise the cost and difficulty of this sort of attack.
- wolfgke 8y ago> It would significantly raise the cost and difficulty of this sort of attack. In my opinion, modifying the board layout with the additional chip and modifying the production process for the server boards stealthily already has a pretty high cost and difficulty.
- rjst01 8y ago> already has a pretty high cost and difficulty That's true, but properly implemented secure boot could serve to increase it by an order of magnitude.