Meta tags:
description= Hastily-written news/info on the firmware security/development communities, sorry for the typos.;
Headings (most frequently used words):
uefi, firmware, security, and, to, secure, boot, intel, for, from, common, with, on, dell, bios, updates, microsoft, code, duktape, fujitsu, redfish, samples, end, coreboot, platform, in, considerations, follow, p2im, scalable, hardware, independent, testing, via, automatic, peripheral, interface, modeling, sentinal, labs, moving, sense, knowledge, about, actually, dumping, anvil, ventures, defeating, symlink, attacks, acpiparse, utility, which, prints, info, acpi, tables, pfs, assembler, script, that, modifies, be, downgrade, able, 18, advisories, zmk, modern, open, source, keyboard, engineering, data, breach, including, internals, offers, dbx, guidance, defn, third, plugin, visual, studio, port, of, the, embeddable, javascript, engine, boothole, grub, vulnerability, irmc, scripting, modular, framework, embedded, systems, address, sanitizer, integration, arm, apple, checklists, overlaps, gaps, fwts, ported, risc, potential, verified, support, barbara, iot, new, os, ibm, policy, based, governance, trusted, container, ietf, draft, richardson, secdispatch, idevid, 01, operational, manufacturer, installed, keys, anchors, disclaimers, us, search, tags, archives, blogs, only, shows, first, 50, posts, navigation,
Text of the page (most frequently used words):
the (154), #security (100), intel (94), firmware (82), for (75), https (71), com (58), and (54), news (48), info (47), development (46), hastily (44), #written (44), communities (44), sorry (44), typos (44), www (42), 2020 (41), advisory (38), blog (37), uefi (30), html (22), comment (21), august (21), content (20), leave (20), hucktech (20), org (19), july (19), boot (19), center (19), blogs (18), that (18), secure (17), with (16), this (15), 2019 (15), github (14), there (14), from (13), 2016 (13), microsoft (13), has (13), 2017 (12), 2018 (12), devices (12), risc (11), new (11), fujitsu (11), coreboot (10), project (10), arm (10), are (10), their (10), hardware (10), linux (9), platform (9), 2015 (9), not (9), based (8), software (8), oracle (8), redfish (8), which (8), works (8), support (8), framework (8), code (8), rss (7), device (7), may (7), windows (7), bios (7), ietf (7), embedded (7), can (7), systems (7), testing (7), source (6), planet (6), search (6), ibm (6), android (6), april (6), june (6), chipsec (6), posts (6), about (6), how (6), verified (6), test (6), lists (6), more (6), list (6), update (6), duktape (6), have (5), other (5), feed (5), freebsd (5), september (5), october (5), november (5), december (5), january (5), february (5), march (5), iot (5), fwts (5), data (5), port (5), also (5), but (5), issues (5), modules (5), our (5), server (5), dbx (5), zmk (5), peripheral (5), p2im (5), site (4), just (4), enterprise (4), open (4), ubuntu (4), trust (4), page (4), first (4), apple (4), amd (4), use (4), working (4), anima (4), any (4), colinianking (4), tests (4), address (4), part (4), updates (4), samples (4), including (4), grub (4), vulnerability (4), dump (4), tmk (4), qmk (4), keyboard (4), series (4), dell (4), common (4), you (3), view (3), wordpress (3), lenovo (3), developer (3), linaro (3), debian (3), red (3), hat (3), reverse (3), engineering (3), cyber (3), developers (3), home (3), only (3), edk2 (3), acpi (3), tools (3), datatracker (3), draft (3), considerations (3), keys (3), time (3), all (3), out (3), article (3), found (3), web (3), colin (3), suite (3), ported (3), work (3), today (3), wiki (3), using (3), firmwaresecurity (3), some (3), research (3), these (3), information (3), one (3), should (3), might (3), makes (3), acs (3), docs (3), run (3), useful (3), sanitizer (3), fpga (3), irmc (3), sample (3), access (3), been (3), third (3), plugin (3), visual (3), studio (3), guidance (3), interface (3), dev (3), mechanical (3), while (3), real (3), wireless (3), acpiparse (3), symlink (3), refresher (3), spi (3), flash (3), memory (3), manage (2), log (2), sign (2), subscribed (2), subscribe (2), bunnie (2), purism (2), system76 (2), edu (2), community (2), sage (2), asset (2), intertech (2), intelligence (2), kali (2), ixsystems (2), inc (2), storage (2), servers (2), tizen (2), standards (2), multiple (2), categories (2), fedora (2), people (2), opensuse (2), xen (2), fsf (2), foundation (2), bootlin (2), discover (2), official (2), bsd (2), iotivity (2), replicant (2), executive (2), cisco (2), möbius (2), strip (2), msdn (2), rapid7 (2), threatpost (2), product (2), incident (2), response (2), team (2), schneier (2), nvm (2), express (2), malwarebytes (2), sniablog (2), w00tsec (2), broadcom (2), connectedbroadcom (2), connected (2), chromium (2), llvm (2), follow (2), shows (2), 112 (2), archives (2), usb (2), tpm (2), macos (2), canonical (2), sponsored (2), preos (2), disclaimers (2), documents (2), richardson (2), secdispatch (2), idevid (2), provides (2), private (2), public (2), anchors (2), group (2), technologies (2), was (2), each (2), day (2), secl (2), cloud (2), computing (2), cases (2), policy (2), governance (2), trusted (2), container (2), discussing (2), txt (2), raise (2), level (2), your (2), barbaraiot (2), guessing (2), closed (2), requires (2), name (2), given (2), unclear (2), operating (2), system (2), called (2), barbara (2), ian (2), king (2), fosstodon (2), off (2), http (2), between (2), centric (2), except (2), nothing (2), defender (2), presume (2), does (2), unknnown (2), documentation (2), lacking (2), x64 (2), sbsa (2), blob (2), master (2), aarch64 (2), technical (2), non (2), after (2), vulnerabilities (2), half (2), gaps (2), gsoc (2), sharma (2), integration (2), paper (2), approach (2), where (2), analysis (2), variety (2), michael (2), end (2), mmurayama (2), indexdownload (2), asp (2), softwareguid (2), see (2), python (2), scripts (2), controller (2), via (2), redhat (2), cert (2), vuls (2), 174059 (2), embeddable (2), javascript (2), engine (2), build (2), defn (2), extension (2), like (2), files (2), certs (2), vulnerable (2), zmkfirmware (2), projects (2), keyboards (2), hope (2), into (2), boards (2), wifi (2), 00337 (2), 00355 (2), board (2), 00367 (2), drivers (2), 00369 (2), 00375 (2), nuc (2), 00376 (2), raid (2), driver (2), 00377 (2), 00378 (2), 00379 (2), 00384 (2), 00386 (2), 00387 (2), 00392 (2), 00394 (2), 00396 (2), 00399 (2), 00406 (2), 00411 (2), pfs (2), assembler (2), script (2), downgrade (2), able (2), file (2), utility (2), tables (2), anvilventures (2), defeating (2), attacks (2), anvil (2), technique (2), partition (2), labs (2), sentinelone (2), moving (2), sense (2), knowledge (2), actually (2), dumping (2), debug (2), fuzz (2), assaf_carlsbad (2), liba2k (2), mine (2), went (2), online (2), merely (2), next (2), will (2), innovative (2), discuss (2), techniques (2), feng (2), long (2), fuzzing (2), limited (2), independent (2), scalable (2), must, post, logged, loading, comments, collapse, bar, subscriptions, reader, report, privacy, already, account, now, join, 231, subscribers, another, world, desktop, phoenix, phoenix_technologies_bios, atom, xml, technet, aspx, mcafee, 160, 164, 137, 129, 143, 101, 103, 102, 110, 100, 168, 116, 105, 107, select, month, vincent, zimmer, forum, tianocore, spectre, smm, rust, qemu, nikolaj, schlej, meltdown, matthew, garrett, job, posting, sgx, amt, google, event, efi, ltd, ami, tags, linkedin, affiliate, links, guarantees, explicit, implied, careful, older, navigation, doc, document, nomenclature, describe, ways, manufacturers, internet, storing, sandelman, huawei, authors, well, when, had, bandwidth, read, rfcs, came, sigh, operational, manufacturer, installed, uses, libraries, library, attest, utilize, features, enable, critical, confidential, articles, they, such, bootguard, medium, yet, pretty, submit, email, contact, link, broken, encryption, exposed, network, services, mentions, vagueness, say, chrome, something, else, what, flavor, interacts, relatively, madrid, spain, daily, searches, potential, got, passed, regression, seeing, get, updated, firmwaretestsuite, infradead, pipermail, riscv, 001248, atish, western, digital, professors, please, suggest, grad, student, thanks, wonder, delta, wish, specific, make, tested, vice, versa, obviously, entries, others, users, know, isas, maybe, coverage, future, processors, eficheck, testcase, checklist, distinction, aarch32, intended, vendor, machines, consumer, prevent, leakage, strongly, recommended, platforms, production, scrubbed, running, x86, amd64, mac, own, handful, checking, tool, separate, checks, publicly, viewable, vendors, wondering, much, overlap, find, additional, checklists, overlaps, mail, hyperkitty, thread, pvafqqzkojxk26m44i7pegnbjmwouj5j, hello, everyone, harshit, hst, irc, add, feature, arxiv, abs, 2007, 09071, present, primitives, cryptographic, deployed, environments, communication, channels, insecure, implementation, flexible, adapted, regards, available, resources, constraints, resilient, attack, vectors, experimental, setup, demonstrates, feasibility, implementing, demonstrate, adaptability, performance, experiments, indicate, procedure, 1183kb, image, could, achieved, manner, under, seconds, solon, falas, charalambos, konstantinou, maria, modular, few, here, blogspot, 85dbc785, b759, 4cde, a1d3, c335b5ec7c1d, ced64cae, a20c, 494e, 91fe, 66adad0dbfd2, ansible, integrated, remote, management, primergy, beyond, ones, dozen, scripting, errata, rhsa, 3217, grub2bootloader, alerts, notices, usn, 4432, gnu, archive, devel, msg00034, eclypsium, theres, hole, case, reading, boothole, tuviannavy, released, nov, libc, shell, application, succeeded, confirmed, unkemptarc99, helps, points, definition, keywords, pcds, guids, etc, abhishek, musupport, vscode, edkii, really, provided, revoked, otherwise, bad, revocationlistfile, help, 4575994, applying, published, 200011, describes, related, party, unified, extensible, certificate, authority, configuration, susceptible, attacker, who, administrative, privileges, physical, apply, latest, revocation, invalidate, plans, push, further, 2021, knowledgebase, secureboot, offers, theregister, intel_nda_source_code_leak, del, dog, onufumerap, twitter, deletescape, status, 1291405690301550592, apparently, includes, fsp, lots, things, breach, internals, hoping, point, evolution, would, maker, badgelife, addition, focus, evolves, eventually, power, ecosystem, puts, effort, competing, arduino, believe, zephyros, supports, doesn, benroe, awesome, reddit, mechanicalkeyboards, tmk_keyboard, qmk_firmware, either, programmable, layers, macros, many, opportunites, badusb, let, learn, treat, powerful, appropriate, caution, zeyphyr, rtos, guess, main, alternatives, modern, bluetooth, iintel, proset, families, graphics, pac, arria, led, manager, rste, console, compute, m10jnp2sb, improvement, program, mailbox, realsense, d400, uwp, distribution, openvino, toolkit, ssd, dct, thunderbolt, advisories, vuquangtrong, original, modifies, jhand2, small, understands, format, print, them, human, readable, way, prints, releasing, white, describing, bypass, number, split, signed, protected, executables, protection, store, persistent, milvich, ventures, researchers, emulate, begin, ben, thurston, bthurstoncptech, 3vh3w74sym, assaf, carlsbad, nluu4r2lhm, sentinal, ris3, lab, usenix, conference, usenixsecurity20, presentation, _longlu_, interested, scale, due, dependencies, presenting, solution, 30p, welcome, tune, sniqlusyuz, usenixsecurity, bofeng17, dynamic, severely, dependence, poor, scalability, partly, contributing, widespread, propose, continuously, executes, binary, channeling, inputs, shelf, fuzzer, enabling, novel, abstracts, diverse, peripherals, handles, fly, automatically, generated, models, oblivious, designs, generic, implementations, therefore, applicable, wide, range, evaluated, drone, robot, plc, successfully, executed, without, manual, assistance, performed, unveiled, unique, unknown, bugs, alejandro, mera, northeastern, university, automatic, modeling, menu, skip,
Text of the page (random words):
github com mmurayama fujitsu redfish samples see also https github com fujitsu fujitsu ansible irmc integration https support ts fujitsu com indexdownload asp softwareguid ced64cae a20c 494e 91fe 66adad0dbfd2 https support ts fujitsu com indexdownload asp softwareguid 85dbc785 b759 4cde a1d3 c335b5ec7c1d there are a few blog posts on fujitsu redfish here http mmurayama blogspot com search q redfish a modular end to end framework for secure firmware updates on embedded systems july 20 2020 hucktech leave a comment by solon falas charalambos konstantinou maria k michael in this paper we present a framework for secure firmware updates on embedded systems the approach is based on hardware primitives and cryptographic modules and it can be deployed in environments where communication channels might be insecure the implementation of the framework is flexible as it can be adapted in regards to the iot device s available hardware resources and constraints our security analysis shows that our framework is resilient to a variety of attack vectors the experimental setup demonstrates the feasibility of the approach by implementing a variety of test cases on fpga we demonstrate the adaptability and performance of the framework experiments indicate that the update procedure for a 1183kb firmware image could be achieved in a secure manner under 1 73 seconds https arxiv org abs 2007 09071 coreboot address sanitizer integration with coreboot july 19 2020 hucktech leave a comment hello everyone my name is harshit sharma hst on irc i am working on the project to add the address sanitizer feature to coreboot as a part of gsoc 2020 gsoc address sanitizer part 1 https mail coreboot org hyperkitty list coreboot coreboot org thread pvafqqzkojxk26m44i7pegnbjmwouj5j intel arm microsoft apple platform security checklists overlaps and gaps july 19 2020 hucktech leave a comment so there are a handful of tools for checking for hardware firmware security issues each tool has a separate list of security checks half of which are publicly viewable with gaps from some hardware and os vendors i m wondering how much overlap there is between these security lists that might be useful to port and find additional security issues intel has chipsec for testing the hardware and firmware for security issues it works on intel x86 and intel x64 not amd amd64 it works on mac windows and linux and uefi public can run this on their own device https github com chipsec chipsec wiki vulnerabilities and chipsec modules arm has sbsa acs for testing hardware and firmware security issues it works on arm aarch64 enterprise devices unclear if there is a technical distinction for non enterprise aarch64 device use not aarch32 it works on uefi intended for vendor use on development machines not consumer devices to prevent the leakage of secure information it is strongly recommended that the acs test suite is run only on development platforms if it is run on production systems the system should be scrubbed after running the test suite https github com arm software sbsa acs blob master docs testcase checklist md apple has eficheck for macos it works on intel x64 and i am guessing that it ll also work on future arm processors the list of security tests it makes is unknnown the documentation is lacking microsoft has defender av which has uefi support for windows i presume but do not know it works on all isas that windows does so maybe coverage on intel amd and arm the list of security tests it makes is unknnown the documentation is lacking amd has nothing except for microsoft defender for windows users only linux has nothing except for intel chipsec on intel systems i wonder about the delta between these 4 security lists i wish there was more information from microsoft and apple on the specific tests their tools make are there any from one list that should also be tested on the other lists and vice versa obviously some entries are platform centric but there are others that might not be any professors out there please suggest a grad student do some research on the intel and arm security lists thanks fwts ported to risc v july 19 2020 hucktech leave a comment re https firmwaresecurity com 2016 05 08 uefi ported to risc v atish of western digital is using fwts to test the risc v port of uefi on linux http lists infradead org pipermail linux riscv 2020 july 001248 html https wiki ubuntu com firmwaretestsuite colin of canonical has updated fwts to have a risc v port day off work today seeing if i can get fwts to work on risc v colin ian king colinianking fosstodon org colinianking july 17 2020 got the firmware test suite ported and passed all the regression tests on risc v o colin ian king colinianking fosstodon org colinianking july 18 2020 potential verified boot support in barbara iot new os july 19 2020 july 19 2020 hucktech leave a comment there is a relatively new operating system called barbara iot based out of madrid spain which is new to my daily verified boot searches their security page mentions verified boot given the vagueness of their web site i can t say if this is linux android chrome verified boot or something else unclear what flavor s of platform firmware the os interacts with raise the security level of your devices with verified boot data encryption and no exposed network services have not found the source to the os yet i m guessing closed source their web site is pretty closed it requires you to submit name email contact info to view any data on their os their home page link to their developers page is broken https barbaraiot com https barbaraiot com security view at medium com raise the security level of your devices with verified boot ibm policy based governance in a trusted container platform july 17 2020 hucktech leave a comment ibm has a new article discussing how they secure their cloud discussing security technologies such as tpm intel txt and intel bootguard https developer ibm com articles policy based governance in trusted container platform project uses intel security libraries for data center intel secl dc a library that discover attest and utilize intel security features to enable critical cloud security and confidential computing use cases https 01 org intel secl ietf draft richardson secdispatch idevid considerations 01 security and operational considerations for manufacturer installed keys and anchors july 16 2020 hucktech leave a comment there was a time when i had bandwidth to read all new ietf rfcs and i ds that came out each day sigh there is a new ietf internet draft from the anima working group about storing private keys in embedded devices sandelman software works and huawei technologies are authors there are other documents from this working group as well this document provides a nomenclature to describe ways in which manufacturers secure private keys and public trust anchors in devices https datatracker ietf org doc draft richardson secdispatch idevid considerations https datatracker ietf org wg anima about https datatracker ietf org wg anima documents https tools ietf org wg anima posts navigation older posts disclaimers no guarantees explicit or implied be careful working with firmware affiliate links in use sponsored by preos security follow us x x x rss feed rss feed linkedin github search search for tags acpi amd ami android apple arm arm ltd bios canonical chipsec coreboot debian edk2 efi event freebsd fwts google hp ibm intel intel amt intel me intel sgx iot job posting lenovo linaro linux macos matthew garrett meltdown microsoft nikolaj schlej qemu redfish red hat risc v rust secure boot smm spectre tianocore tpm u boot uefi uefi forum usb vincent zimmer windows archives archives select month august 2020 12 july 2020 29 june 2020 45 may 2020 50 april 2020 32 march 2020 22 february 2020 30 january 2020 20 december 2019 30 november 2019 30 october 2019 38 september 2019 22 august 2019 56 july 2019 54 june 2019 31 may 2019 64 april 2019 73 march 2019 83 february 2019 66 january 2019 88 december 2018 77 november 2018 95 october 2018 107 september 2018 54 august 2018 105 july 2018 116 june 2018 168 may 2018 112 april 2018 112 march 2018 90 february 2018 100 january 2018 110 december 2017 102 november 2017 93 october 2017 87 september 2017 75 august 2017 103 july 2017 87 june 2017 94 may 2017 95 april 2017 101 march 2017 85 february 2017 90 january 2017 83 december 2016 45 november 2016 33 october 2016 56 september 2016 70 august 2016 82 july 2016 76 june 2016 59 may 2016 89 april 2016 72 march 2016 52 february 2016 95 january 2016 143 december 2015 93 november 2015 129 october 2015 137 september 2015 164 august 2015 160 july 2015 81 june 2015 39 may 2015 55 april 2015 4 search for blogs i follow only shows first 50 android android developers blog qt blog llvm project blog chromium blog broadcom connectedbroadcom connected w00tsec sniablog org https blogs mcafee com home page feed malwarebytes blog rss blog nvm express schneier on security ibm product security incident response team threatpost rapid7 blog blogs technet com rss aspx search msdn cyber trust blog blog möbius strip reverse engineering executive platform cisco blogs replicant iotivity blogs official pc bsd blog bootlin freebsd foundation planet freebsd ubuntu blog fsf news oracle blogs oracle blogs oracle blogs oracle blogs blog xen project red hat blog planet opensuse fedora people planet debian blog tizen an open source standards based software platform for multiple device categories ixsystems inc enterprise storage servers kali linux linaro intelligence blog asset intertech sage coreboot developer blogs blogs phoenix com phoenix_technologies_bios atom xml lenovo edu community system76 blog rss feed purism bunnie s blog blog at wordpress com android hastily written news info on the firmware security development communities sorry for the typos android developers blog hastily written news info on the firmware security development communities sorry for the typos qt blog hastily written news info on the firmware security development communities sorry for the typos llvm project blog hastily written news info on the firmware security development communities sorry for the typos chromium blog hastily written news info on the firmware security development communities sorry for the typos broadcom connectedbroadcom connected hastily written news info on the firmware security development communities sorry for the typos w00tsec hastily written news info on the firmware security development communities sorry for the typos sniablog org hastily written news info on the firmware security development communities sorry for the typos malwarebytes hastily written news info on the firmware security development communities sorry for the typos blog rss hastily written news info on the firmware security development communities sorry for the typos blog nvm express hastily written news info on the firmware security development communities sorry for the typos schneier on security hastily written news info on the firmware security development communities sorry for the typos ibm product security incident response team hastily written news info on the firmware security development communities sorry for the typos threatpost rapid7 blog hastily written news info on the firmware security development communities sorry for the typos hastily written news info on the firmware security development communities sorry for the typos search msdn hastily written news info on the firmware security development communities sorry for the typos cyber trust blog blog möbius strip reverse engineering hastily written news info on the firmware security development communities sorry for the typos executive platform cisco blogs hastily written news info on the firmware security development communities sorry for the typos replicant hastily written news info on the firmware security development communities sorry for the typos iotivity blogs hastily written news info on the firmware security development communities sorry for the typos official pc bsd blog discover the desktop bootlin hastily written news info on the firmware security development communities sorry for the typos freebsd foundation hastily written news info on the firmware security development communities sorry for the typos planet freebsd ubuntu blog hastily written news info on the firmware security development communities sorry for the typos fsf news hastily written news info on the firmware security development communities sorry for the typos oracle blogs oracle blogs hastily written news info on the firmware security development communities sorry for the typos oracle blogs oracle blogs hastily written news info on the firmware security development communities sorry for the typos blog xen project hastily written news info on the firmware security development communities sorry for the typos red hat blog hastily written news info on the firmware security development communities sorry for the typos planet opensuse hastily written news info on the firmware security development communities sorry for the typos fedora people hastily written news info on the firmware security development communities sorry for the typos planet debian hastily written news info on the firmware security development communities sorry for the typos blog hastily written news info on the firmware security development communities sorry for the typos tizen an open source standards based software platform for multiple device categories hastily written news info on the firmware security development communities sorry for the typos ixsystems inc enterprise storage servers hastily written news info on the firmware security development communities sorry for the typos kali linux hastily written news info on the firmware security development communities sorry for the typos linaro hastily written news info on the firmware security development communities sorry for the typos intelligence blog asset intertech hastily written news info on the firmware security development communities sorry for the typos sage hastily written news info on the firmware security development communities sorry for the typos coreboot developer blogs news from coreboot world hastily written news info on the firmware security development communities sorry for the typos lenovo edu community hastily written news info on the firmware security development communities sorry for the typos system76 blog rss feed hastily written news info on the firmware security development communities sorry for the typos purism just another wordpress com site bunnie s blog hastily written news info on the firmware security development communities sorry for the typos subscribe subscribed firmware security join 231 other subscribers sign me up already have a wordpress com account log in now privacy firmware security subscribe subscribed sign up log in report this content view site in reader manage subscriptions collapse this bar loading comments you must ...
|