On Tue, 25 Apr 2017 22:38:15 +0800 Shawn citypw@gmail.com wrote:
slide: https://www.troopers.de/downloads/troopers17/TR17_ME11_Static.pdf
Thanks a lot! This is very interesting.
I probably missed something about the ROM bypass: Since you have flash images with ROM Bypass in use, what would prevent someone from: - Finding and buying hardware with ROM bypass enabled. Are there any business or consumers laptops/desktops/workstation with such feature? - Writing your own code in the ROM ME partition and executing it.
Denis.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
On 05/01/2017 07:13 PM, Denis 'GNUtoo' Carikli wrote:
On Tue, 25 Apr 2017 22:38:15 +0800 Shawn citypw@gmail.com wrote:
slide: https://www.troopers.de/downloads/troopers17/TR17_ME11_Static.pdf
Thanks a lot! This is very interesting.
I probably missed something about the ROM bypass: Since you have flash images with ROM Bypass in use, what would prevent someone from:
- Finding and buying hardware with ROM bypass enabled. Are there any business or consumers laptops/desktops/workstation with such feature?
- Writing your own code in the ROM ME partition and executing it.
Denis.
I would expect the signature checks by the hardware would stop execution of unsigned ROM ME code.
- -- Timothy Pearson Raptor Engineering +1 (415) 727-8645 (direct line) +1 (512) 690-0200 (switchboard) https://www.raptorengineering.com
Hello Denis,
Tuesday, May 2, 2017, 2:13:13 AM, you wrote:
DGC> On Tue, 25 Apr 2017 22:38:15 +0800 DGC> Shawn citypw@gmail.com wrote:
slide: https://www.troopers.de/downloads/troopers17/TR17_ME11_Static.pdf
DGC> Thanks a lot! This is very interesting.
DGC> I probably missed something about the ROM bypass: Since you have flash DGC> images with ROM Bypass in use, what would prevent someone from: DGC> - Finding and buying hardware with ROM bypass enabled. Are there any DGC> business or consumers laptops/desktops/workstation with such feature? DGC> - Writing your own code in the ROM ME partition and executing it.
ROM Bypass only works on pre-production hardware (e.g. reference boards used for initial development). On production hw it's ignored and mask ROM is always used.
ROM Bypass only works on pre-production hardware (e.g. reference boards used for initial development). On production hw it's ignored and mask ROM is always used.
Is it possible to buy a reference board if you aren't an OEM?