2009/11/29 Mansour Moufid <[email protected]>:
Google's new OS claims to prevent exactly this sort of attack by using
"custom" firmware to conduct regular checks:
http://www.youtube.com/watch?v=A9WVmNfgjtQ#t=2m24s
Apparently, the key used to check the kernel for modification is kept
in "read-only" firmware, along with "verifier logic" (hash test
cases?). If they're successful, perhaps Gentoo Hardened could adopt
these methods.
Well, at least a part of that firmware should be overwritable with new hashes 
or otherwise I can assure you data tampering wouldn't be as dangerous as 
exploit using on outdated kernels.

The thing is, knowing where that firmware is you can reflash it with your new 
hashes so you'll foil the scheme. Of course this could take some time on a 
laptop (15 minutes tops) and you can be sure that somebody interested can get a 
replacement for the tamper proof parts.

BTW: I rather use a 1$ rubber hose.

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to