26.03.2013 Views

Evil Maid Just Got Angrier - Why Full-Disk Encryption ... - CanSecWest

Evil Maid Just Got Angrier - Why Full-Disk Encryption ... - CanSecWest

Evil Maid Just Got Angrier - Why Full-Disk Encryption ... - CanSecWest

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

The Solution is Simple<br />

<strong>Just</strong> let BitLocker rely on all platform manufacturers to protect the UEFI<br />

BIOS from programmable SPI writes by malware, allow only signed UEFI<br />

BIOS updates, protect authorized update software, update the boot block<br />

(SEC/PEI code) securely, correctly program and protect SPI Flash<br />

descriptor, lock the SPI controller configuration, and not introduce a single<br />

bug in all of this, of course.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!