From: Pavel Machek <pavel@ucw.cz>
To: James Morris <jmorris@namei.org>
Cc: Chris Wright <chrisw@sous-sol.org>,
Joseph Cihula <joseph.cihula@intel.com>,
Ingo Molnar <mingo@elte.hu>,
linux-kernel@vger.kernel.org, arjan@linux.intel.com,
hpa@zytor.com, andi@firstfloor.org, jbeulich@novell.com,
peterm@redhat.com, gang.wei@intel.com, shane.wang@intel.com
Subject: Re: [RFC v4][PATCH 2/2] intel_txt: Intel(R) TXT and tboot kernel support
Date: Mon, 24 Aug 2009 11:43:54 +0200 [thread overview]
Message-ID: <20090824094353.GE25591@elf.ucw.cz> (raw)
In-Reply-To: <alpine.LRH.2.00.0906290828200.29509@tundra.namei.org>
On Mon 2009-06-29 08:46:07, James Morris wrote:
> On Fri, 26 Jun 2009, Pavel Machek wrote:
>
> >
> > > Also, hardware security measures such as TXT are important in providing
> > > stronger mechanisms to ensure that kernel security mechanisms are
> > > functioning correctly.
> >
> > I don't get it. How does TXT help kernel security mechanisms?
>
> Kernel security mechanisms can be subverted and bypassed in the case of an
> exploitable kernel vulnerability, or from exploitable buggy hardware (e.g.
> which can access the entire host's memory via DMA). Attacks on kernel
> security mechanisms have been describe in detail, see:
> http://www.phrack.com/issues.html?issue=66&id=15#article
>
> This is close to impossible to solve from within the kernel alone.
> Hardware support is required to allow protection of the IO space (e.g. via
> IOMMU/VT-d), and to allow verification of the kernel itself (via
> TXT).
So... you can exploit kernel security holes. How does intel TXT help?
AFAICT it does not. From what I see, intel TXT only prevents user
from physically tampering with his own machine. Preventing user from
tampering with his own machine is immoral to me, and from what I've
seen it will be ineffective as soon as user suspends the machine, uses
some liquid nitrogen, does whatever he needs with the RAM modules, and
then places them back.
Pavel
--
(english) http://www.livejournal.com/~pavelmachek
(cesky, pictures) http://atrey.karlin.mff.cuni.cz/~pavel/picture/horses/blog.html
prev parent reply other threads:[~2009-08-24 9:44 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-06-05 21:38 Joseph Cihula
2009-06-12 5:12 ` James Morris
2009-06-12 10:23 ` Andi Kleen
2009-06-19 15:05 ` Pavel Machek
2009-06-19 17:52 ` Valdis.Kletnieks
2009-06-19 19:11 ` Alan Cox
2009-06-19 20:27 ` Alan Cox
2009-06-22 1:33 ` James Morris
2009-06-19 21:22 ` Pavel Machek
2009-06-19 18:34 ` Chris Wright
2009-06-22 1:54 ` James Morris
2009-06-26 21:30 ` Pavel Machek
2009-06-28 22:46 ` James Morris
2009-08-24 9:43 ` Pavel Machek [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20090824094353.GE25591@elf.ucw.cz \
--to=pavel@ucw.cz \
--cc=andi@firstfloor.org \
--cc=arjan@linux.intel.com \
--cc=chrisw@sous-sol.org \
--cc=gang.wei@intel.com \
--cc=hpa@zytor.com \
--cc=jbeulich@novell.com \
--cc=jmorris@namei.org \
--cc=joseph.cihula@intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@elte.hu \
--cc=peterm@redhat.com \
--cc=shane.wang@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome