4 ms·
An amazing write-up. Although I am using my EE training a lot more at work these days, and I've designed my fair share of MCU (and USB, FPGA, analog...) project
by csirac2 12y ago
An amazing write-up. Although I am using my EE training a lot more at work these days, and I've designed my fair share of MCU (and USB, FPGA, analog...) projects I've never found the time to dip into learning even a fraction of the detail presented here on low-level modern x86 architecture.
For me, reading this really hammers home just how feasible evil maid type attacks really are (considering attacks aimed at defeating Eg. Full disk encryption). But at the same time, if I am still typing the passphrase for my encrypted disks at each boot, simply filming me use my laptop would seem easier... So using that logic, I have been working on passwordless unlock before fiddling with the very tedious task of maintaining a SecureBoot Linux installation.
Can anyone say how strong the x86/TPM-equipped machines out there are against malicious firmware updates, assuming one has their BIOS admin password set?
- walterbell 12y ago> Can anyone say how strong the x86/TPM-equipped machines out there are against malicious firmware updates, assuming one has their BIOS admin password set? A machine with VT-d (IOMMU), TPM and TXT is needed. http://theinvisiblethings.blogspot.com/2011/09/anti-evil-maid.html http://theinvisiblethings.blogspot.com/2011/09/anti-evil-mai...
- jhallenworld 12y agoHeh, but be careful of (intentional?) bugs. I have seen some versions of UEFI which do not measure option ROMs for example. Look for changes to pcr-2 and pcr-3 when you plug or unplug cards with option ROMs: cat /sys/devices/* /* /pcrs