Live data from Hacker News

AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

seclists.org

21–30 of 99 posts

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#21
post #17
post #15

Earlier quoted context omitted.

Hopefully 2018 will be the year where CPU manufacturers finally start taking security seriously.

Yeah sure and I bet this will be the year of the Linux Desktop, too.

thats a funny way of spelling "Linux Gaming"

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#24
post #23

Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes the hassle worth it.

What makes you think pen and paper is secure?

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#25
post #24
post #23

Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes the hassle worth it.

What makes you think pen and paper is secure?

Pen and paper in a good old fashioned steel cabinet (you can get those with some nice solid wood enclosing as well) require actual physical access to read.

However, side channels exist. If you write classified information on a correspondence pad, then the pad itself becomes a classified item, too. Obviously.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#26
post #24
post #23

Oh, god. At this point I no longer trust ANY computer for mission-critical business at my company. We're going back to pen and paper. The extra safety makes the hassle worth it.

What makes you think pen and paper is secure?

Because you can't easily get away with several million documents in your trenchcoat.

A data breach would be catastrophic for us. We lose less money this way.

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#27
post #24

Earlier quoted context omitted.

What makes you think pen and paper is secure?

Pen and paper in a good old fashioned steel cabinet (you can get those with some nice solid wood enclosing as well) require actual physical access to read. However, side channels exist. If you write classified information on a correspondence pad, then the pad itself becomes a classified item, too. Obviously.

Who gets keys to the cabinet? How do you know they haven't been duplicated?

What if there is a fire? Do you keep a copy of the files somewhere? How do you control access to those?

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#28
post #26
post #24

Earlier quoted context omitted.

What makes you think pen and paper is secure?

Because you can't easily get away with several million documents in your trenchcoat. A data breach would be catastrophic for us. We lose less money this way.

Do you?

Can a business that runs on pen and paper compete in 2018? Have you included lost revenue due to inefficiency?

Re: AMD PSP: Firmware TPM Remote Code Execution via Crafted EK Certificate

#30
post #27

Earlier quoted context omitted.

Pen and paper in a good old fashioned steel cabinet (you can get those with some nice solid wood enclosing as well) require actual physical access to read. However, side channels exist. If you write classified information on a correspondence pad, then the pad itself becomes a classified item, too. Obviously.

Who gets keys to the cabinet? How do you know they haven't been duplicated? What if there is a fire? Do you keep a copy of the files somewhere? How do you control access to those?

You get literally the exact same set of problems with computers, plus all problems computers bring to the table for free.
Post reply on HN