Re: Just update the microcode (was: Re: defending against evil in all layers of hardware and software)

2008-04-29 Thread Sebastian Krahmer
The "signature" in the microcode update has not the same meaning as within crypto. For intel chips it has 31bits and basically contains a revision number. The requirements for the BIOS for checking microcode updates are in short: check the crc and ensure that older revisions cant replace new ones

Re: Just update the microcode (was: Re: defending against evil in all layers of hardware and software)

2008-04-29 Thread John Ioannidis
nce monitor somewhere in it that you can truly trust. - Alex That we agree on! /ji - Original Message - From: "John Ioannidis" <[EMAIL PROTECTED]> To: Cryptography Subject: Just update the microcode (was: Re: defending against evil in all layers of hardware and soft

Re: Just update the microcode (was: Re: defending against evil in all layers of hardware and software)

2008-04-29 Thread alex
makes designing a good security system a real challenge. You need a reference monitor somewhere in it that you can truly trust. - Alex > - Original Message - > From: "John Ioannidis" <[EMAIL PROTECTED]> > To: Cryptography > Subject: Just update the micr

Just update the microcode (was: Re: defending against evil in all layers of hardware and software)

2008-04-28 Thread John Ioannidis
Intel and AMD processors can have new microcode loaded to them, and this is usually done by the BIOS. Presumably there is some asymmetric crypto involved with the processor doing the signature validation. A major power that makes a good fraction of the world's laptops and desktops (and hence