Skip to content

Comment on Prevent cold boot attacks using TRESORparent

Comments

Yes -- it's pretty feasible for there to be lots of evil chips on a normal motherboard. It's not feasible for anyone but Intel to attack an E5 CPU right now, and probably not for the next ~2y, unless there's an implementation bug -- no one else can make a chip that dense and fast right now.

The BIOS is probably the lowest hanging fruit for an attacker now. Most trusted boot doesn't even really check the BIOS in any real way, it starts sometime after the BIOS.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.