It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
Replacing exploit-ridden firmware with a Linux kernel Replacing exploit-ridden firmware with a Linux kernel
FAQ Members List Calendar Search Today's Posts Mark Forums Read


Replacing exploit-ridden firmware with a Linux kernel
Reply
 
Thread Tools
Old 31st October 2017, 05:15   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 148,618
Stefan Mileschin Freshly Registered
Default Replacing exploit-ridden firmware with a Linux kernel

Two weeks ago, security researchers managed to disable the Intel Management Engine, and last week, Google held a talk at the Open Source Summit (née LinuxCon) in which they unveiled their plans to completely (well, almost completely) replace every bit of code between the operating system you know about (Windows, Linux, BSD, whatever) and the bare metal x86 processor (Intel-only, for now). With the WikiLeaks release of the vault7 material, the security of the UEFI (Unified Extensible Firmware Interface) firmware used in most PCs and laptops is once again a concern. UEFI is a proprietary and closed-source operating system, with a codebase almost as large as the Linux kernel, that runs when the system is powered on and continues to run after it boots the OS (hence its designation as a "Ring -2 hypervisor"). It is a great place to hide exploits since it never stops running, and these exploits are undetectable by kernels and programs. Our answer to this is NERF (Non-Extensible Reduced Firmware), an open source software system developed at Google to replace almost all of UEFI firmware with a tiny Linux kernel and initramfs. The initramfs file system contains an init and command line utilities from the u-root project (http://u-root.tk/), which are written in the Go language. Both the slides from the talk and the video are available.

http://osnews.com/story/30062/Replac...a_Linux_kernel
Stefan Mileschin is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
AMD's Ryzen Will Really Like a Newer Linux Kernel Stefan Mileschin WebNews 0 2nd March 2017 05:35
Linux exploit gives any user full access in five seconds Stefan Mileschin WebNews 0 25th October 2016 07:51
Samsung says data-eating TRIM bug is a Linux kernel problem Stefan Mileschin WebNews 0 23rd July 2015 10:43
Microsoft patches bug-ridden December firmware upgrade for Surface Pro 2 Stefan Mileschin WebNews 0 20th January 2014 11:29
New version of Linux kernel appears Stefan Mileschin WebNews 0 2nd July 2013 06:31
Torvalds furious at latest Linux kernel Stefan Mileschin WebNews 0 11th June 2013 07:06
Google working on experimental 3.8 Linux kernel for Android Stefan Mileschin WebNews 0 1st March 2013 07:17
Linux kernel patches surface for Chromebook Pixel Stefan Mileschin WebNews 0 22nd February 2013 07:43
Five Years Of Linux Kernel Benchmarks: 2.6.12 Through 2.6.37 jmke WebNews 1 4th November 2010 16:35
Linux 2.6.26 Kernel Benchmarks jmke WebNews 0 18th July 2008 09:01

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 10:03.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO