Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753054AbZFSTM6 (ORCPT ); Fri, 19 Jun 2009 15:12:58 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1751419AbZFSTMu (ORCPT ); Fri, 19 Jun 2009 15:12:50 -0400 Received: from lxorguk.ukuu.org.uk ([81.2.110.251]:38971 "EHLO lxorguk.ukuu.org.uk" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751370AbZFSTMt (ORCPT ); Fri, 19 Jun 2009 15:12:49 -0400 Date: Fri, 19 Jun 2009 20:11:59 +0100 From: Alan Cox To: Valdis.Kletnieks@vt.edu Cc: Pavel Machek , James Morris , Joseph Cihula , Ingo Molnar , linux-kernel@vger.kernel.org, arjan@linux.intel.com, hpa@zytor.com, andi@firstfloor.org, Chris Wright , jbeulich@novell.com, peterm@redhat.com, gang.wei@intel.com, shane.wang@intel.com Subject: Re: [RFC v4][PATCH 2/2] intel_txt: Intel(R) TXT and tboot kernel support Message-ID: <20090619201159.35d259bb@lxorguk.ukuu.org.uk> In-Reply-To: <33858.1245433922@turing-police.cc.vt.edu> References: <4A299051.40405@intel.com> <20090619150514.GE1389@ucw.cz> <33858.1245433922@turing-police.cc.vt.edu> X-Mailer: Claws Mail 3.7.0 (GTK+ 2.14.7; i386-redhat-linux-gnu) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 888 Lines: 20 > "Somebody has screwed with this kernel image, and you're not booting what you > thought you were booting." So I screw with your user space - you can't measure enough to make it save you in a general setup. Too much I can hit changes each boot. For a tiny number of very special cases that are highly controlled it has potential uses. Some of those are evil some are ones with meaningful uses (eg ATM machines) - although attacks there have included hardware attacks outside the PC components too. Personally (and I'm sure Intel disagrees with me) my bigger work is that I can't verify that the magic block of code for tboot is correct. -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/