Earlier quoted context omitted.
Hopefully 2018 will be the year where CPU manufacturers finally start taking security seriously.
Yeah sure and I bet this will be the year of the Linux Desktop, too.
AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
21–30 of 99 posts
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#22Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#23We're going back to pen and paper. The extra safety makes the hassle worth it.
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#24Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes the hassle worth it.
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#25Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes the hassle worth it.
What makes you think pen and paper is secure?
However, side channels exist. If you write classified information on a correspondence pad, then the pad itself becomes a classified item, too. Obviously.
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#26Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes the hassle worth it.
What makes you think pen and paper is secure?
A data breach would be catastrophic for us. We lose less money this way.
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#27Earlier quoted context omitted.
What makes you think pen and paper is secure?
Pen and paper in a good old fashioned steel cabinet (you can get those with some nice solid wood enclosing as well) require actual physical access to read. However, side channels exist. If you write classified information on a correspondence pad, then the pad itself becomes a classified item, too. Obviously.
What if there is a fire? Do you keep a copy of the files somewhere? How do you control access to those?
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#28Earlier quoted context omitted.
What makes you think pen and paper is secure?
Because you can't easily get away with several million documents in your trenchcoat. A data breach would be catastrophic for us. We lose less money this way.
Can a business that runs on pen and paper compete in 2018? Have you included lost revenue due to inefficiency?
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#29"Timeline ======== 09-28-17 - Vulnerability reported to AMD Security Team. 12-07-17 - Fix is ready. Vendor works on a rollout to affected partners. 01-03-18 - Public disclosure due to 90 day disclosure deadline."
Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate
#30Earlier quoted context omitted.
Pen and paper in a good old fashioned steel cabinet (you can get those with some nice solid wood enclosing as well) require actual physical access to read. However, side channels exist. If you write classified information on a correspondence pad, then the pad itself becomes a classified item, too. Obviously.
Who gets keys to the cabinet? How do you know they haven't been duplicated? What if there is a fire? Do you keep a copy of the files somewhere? How do you control access to those?