|
|
Log in / Subscribe / Register

Practical security for 2014

Practical security for 2014

Posted Jan 12, 2014 4:05 UTC (Sun) by dashesy (guest, #74652)
In reply to: Practical security for 2014 by Cyberax
Parent article: Practical security for 2014

Easier, not easy.
While auditing a dis-assembly of a ROM in old BIOS is something an over-suspicious (or critically targeted) agency may endeavor, same task with all the complexity of secure boot is doubly crazy. Also if one could get suspicious of rootkit activity (battery consumption, CPU noise, suspicious network access, ...) in non-secure boot, same activity could be just attributed to the complexity of SecureBoot and ignored, assuming that all is safe because OS booted fine, and so the chain must be secure. The false sense of security.
From practical point of view, if it is harder for OS (and BIOS vendors) to get it right (look at all the problems resulting in non-working systems), then it will be just as hard to validate every once in a while by an audit.


to post comments

Practical security for 2014

Posted Jan 12, 2014 16:10 UTC (Sun) by raven667 (subscriber, #5198) [Link]

> Also if one could get suspicious of rootkit activity (battery consumption, CPU noise, suspicious network access, ...) in non-secure boot, same activity could be just attributed to the complexity of SecureBoot and ignored, assuming that all is safe because OS booted fine, and so the chain must be secure.

I'm sorry but that's total baloney, I don't think anyone but you would try to attribute suspicious network activity, high battery consumption and high CPU usage to the bootloader code having a signature validated before it was run when the system booted.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds