3 ms·
You may believe reinstalling the OS is enough I made no such claim, but verifying bios and firmware signatures (and indeed detecting changes when they happen),
by sc00ter 14y ago
You may believe reinstalling the OS is enough
I made no such claim, but verifying bios and firmware signatures (and indeed detecting changes when they happen), and reinstalling them at scale is not a major challenge with a well managed IT infrastructure.
I can accept however that the Times may well have been running 10 year old PCs, with manual IT management processes, and outdated security software, and that replacement may have been overdue and economically more viable.
- beagle3 14y ago> verifying bios and firmware signatures (and indeed detecting changes when they happen), and reinstalling them at scale is not a major challenge with a well managed IT infrastructure. Can you back up that claim with reference to a system that does that? EVERY single management system I can think of trusts the system to report its status. You can't trust a compromised system to report its status. Assume you have 5,000 desktop computers. How do you set them up so you can verify bios and firmware signatures without forcing a good bios reflash in the first place? (An action that does require soldering or jumper setting on modern motherboards!) > I can accept however that the Times may well have been running 10 year old PCs If you're running your business properly, 3-4 years is the oldest any PC should ever get. If you know a business running 10 year old PCs, tell them to get a new accountant. Today's $300 ATOM netbook (with your 10 year old screen and keyboard) will have positive ROI compared to maintaining a 10 year old machine (The best 2002 Pentium 4 is comparable to a modern ATOM, but needs 5-10 times as much power). You'll be saving money just with energy/cooling costs.
- j_s 14y agoGood point, as in theory both the BIOS and the BIOS flash update routine could be replaced/virtualized... confirming a successful update even though the update was ignored.
- astrange 14y ago> I made no such claim, but verifying bios and firmware signatures (and indeed detecting changes when they happen), and reinstalling them at scale is not a major challenge with a well managed IT infrastructure. It is? How do you do it?
- larrys 14y ago"replacement may have been overdue and economically more viable" Adding to that the fact that the replacement may have been covered by computer crime insurance that they possibly had.