Skip to content

Show HN: The Chinese hardware attack is false

1 pointcyphunk2 comments
On HN

considering the irrationality of executing the memory attacks through hardware mod:

If the device has secure boot in place, whereby memory is signed and sometimes encrypted, any attempt to modify the SPI memory bus, the focal point of discussion thus far, will be useless++. And if secure boot of BMC is not in place then the manufacturer (read `evil chinese') will just modify the memory before shipping. Cheaper, more efficient, less detectable.

What this means is that everyone is looking at the wrong place for origin of attack. It is highly unlikely to be the manufacturer.

++ modification of memory is prevented by secure boot unless that secure boot implementation has a runtime flaw, which can be fixed through software patch.

Comments

instead of 'false' say click bait.

Unable to change title ;)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.