Skip to content

Comment on Prevent cold boot attacks using TRESORparent

Comments

> as long as you trust a tiny subset of it -- potentially just the Intel CPU.

http://www.xakep.ru/post/58104/ (use Google Transalte)

TL;DR

The author has found an undeclared software module (backdoor?) working as a hypervisor in the System Management Block chip on the South Bridge working with Intel CPU with VT virtualization technology.

Yes -- it's pretty feasible for there to be lots of evil chips on a normal motherboard. It's not feasible for anyone but Intel to attack an E5 CPU right now, and probably not for the next ~2y, unless there's an implementation bug -- no one else can make a chip that dense and fast right now.

The BIOS is probably the lowest hanging fruit for an attacker now. Most trusted boot doesn't even really check the BIOS in any real way, it starts sometime after the BIOS.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.