2009/11/29 Mansour Moufid <[email protected]>:
Google's new OS claims to prevent exactly this sort of attack by using "custom" firmware to conduct regular checks: http://www.youtube.com/watch?v=A9WVmNfgjtQ#t=2m24s Apparently, the key used to check the kernel for modification is kept in "read-only" firmware, along with "verifier logic" (hash test cases?). If they're successful, perhaps Gentoo Hardened could adopt these methods.
Well, at least a part of that firmware should be overwritable with new hashes or otherwise I can assure you data tampering wouldn't be as dangerous as exploit using on outdated kernels.
The thing is, knowing where that firmware is you can reflash it with your new hashes so you'll foil the scheme. Of course this could take some time on a laptop (15 minutes tops) and you can be sure that somebody interested can get a replacement for the tamper proof parts. BTW: I rather use a 1$ rubber hose.
signature.asc
Description: OpenPGP digital signature
