Hacker News new | past | comments | ask | show | jobs | submit login

> Boot-level security

You can get pretty far with commodity hardware. Even Secure Boot with custom keys prevents most threats.




IMHO the biggest problem with commodity hardware is IPMI BMCs, a problem so insidious and widespread as to limit the utility of implementing trusted boot. (I designed datacenters for a major bitcoin exchange.) I would hazard a guess that Google's custom hardware has a more intelligent/limited/secure (and crypto-validated firmware based) IPMI implementation, and this contributes far more to security versus commodity hardware than cryptographically secured main processor / system boot.


I agree. Is there any serious effort at making an open source BMC firmware?

At least Intel AMT improves the situation a bit.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: