Post #1498051
2026-02-01 08:52 UTC
@tor
The threat model is any exploit (or bug!) that leads to persistent modification of the software stored on disk. The idea is that after a reboot, you _know_ what software was started (or the attestation fails). The hardware is off-the-shelf standard stuff, only needs a TPM. This is about the integrity of the OS and its payload.
Replies (1)
-
@tor@norden.social 2026-02-01 17:58
@zbyszek Thanks for the explanation. Software integrity is only one side of the coin. The other side is hardware and firmware - see "Bunnie" Huang with his Baochip or UEFI bootkits.