Re: [coreboot] Digging Into The Core of Boot

2017-07-31 Thread ron minnich
if you count chromebooks as the majority of ports, which may be a fair claim, no it's not. On Mon, Jul 31, 2017 at 9:38 AM taii...@gmx.com wrote: > I thought SMI/SMM was disabled in the majority of coreboot ports? > > -- > coreboot mailing list: coreboot@coreboot.org > https://mail.coreboot.org/

Re: [coreboot] Digging Into The Core of Boot

2017-07-31 Thread taii...@gmx.com
I thought SMI/SMM was disabled in the majority of coreboot ports? -- coreboot mailing list: coreboot@coreboot.org https://mail.coreboot.org/mailman/listinfo/coreboot

[coreboot] Digging Into The Core of Boot

2017-07-31 Thread Shawn
Slide: https://recon.cx/2017/montreal/resources/slides/RECON-MTL-2017-DiggingIntoTheCoreOfBoot.pdf Speaking of attack surfaces reduction at runtime, this script might be a workaround: https://github.com/hardenedlinux/Debian-GNU-Linux-Profiles/blob/master/scripts/harbian_fw/fw_hardening_runtime.py