I wonder if any of the people crying "omg secure boot is dead, if I get owned I could have malware forever in my BIOS" are actually running a proper secure boot system with all the obvious backdoorable parts secured (at least those you can do anything about).
-
Show this thread
-
That means all the firmware on your add-in cards and miscellaneous perioherals has to be signed and measured at boot. Everything must have anti-rollback protection. Yes, that includes your Ethernet and USB3 and SAS controllers. And your GPU. And a zillion other things.
2 replies 1 retweet 11 likesShow this thread -
And I hope you're running with a full IOMMU implementation. And you've certainly audited all the drivers to make sure they aren't trivially exploitable (hint: most are). And you're using a TPM to hold all your keys outside the CPU.
2 replies 0 retweets 10 likesShow this thread -
Replying to @marcan42
I don't think any distro (other than maybe Qubes) even enables the IOMMU by default. Kind of a rude discovery when I was trying out vfio.
1 reply 0 retweets 0 likes
And this is how IOMMU support never improves. I had to send in a patch to make my FireWire controller work with IOMMU (hardware bug workaround), and I still get random crap-outs that break Ethernet once in a while.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.