4 ms·
IMO the way they did verified boot is even better. TPM style hardware assisted boot chain verification all the way down to a rolling full root filesystem hash l
by trotsky 16y ago
IMO the way they did verified boot is even better. TPM style hardware assisted boot chain verification all the way down to a rolling full root filesystem hash list.
Sounds like a smartphone sure, except that it doesn't prevent running unsigned code it just detects tampering with standard executables. And it'll let you tamper all you want, it just warns you that they failed and allow you to choose to reload from a known good if you'd like.
Not that disk encryption isn't important, just that I'd bet 99% of data theft isn't local to the machine.
Nice to see a security implementation that is dealing with the current threat level (ie, fucked) but not using it as an excuse to lock out modification
http://www.chromium.org/chromium-os/chromiumos-design-docs/verified-boot http://www.chromium.org/chromium-os/chromiumos-design-docs/v...
- SpikeGronim 16y agoAgreed, finally a use for TPM that isn't customer hostile.