3 ms·
Inclined to agree here. Luke is going on about Intel ME backdoors on Twitter, but in reality there will be a far less crazy explanation for how he got owned.
by bbbbb5 4y ago
Inclined to agree here. Luke is going on about Intel ME backdoors on Twitter, but in reality there will be a far less crazy explanation for how he got owned.
- dannyw 4y agoIn reality a $55 per month colo provider with a history of security incidents is not a reasonable choice for a high security application.
- bbbbb5 4y agoYou can easily protect your hardware from all but the most determined adversaries with extensive physical access. Epoxy in ports, case intrusion detection and locked down boot chain. Use TPM2-totp for verified boot. Your colo provider can be thoroughly owned, your adversaries can have physical access to the server for extended periods of time and still not be able to do anything because you've denied them access to any ports that'd allow DMA. Lots of cheap DIY options for fancy case intrusion detection going way beyond that offered by mfgs. USB camera and some tape?