Alan Cox <alan@lxorguk.ukuu.org.uk> wrote on 08/13/2008 09:40:40 AM:Replacing with alternative hardware is outside the attack model. For this use case, the TCG assumes the user will not be attacking himself. Replacing with software is a valid remote attack. It will be detected through the TCG platform measurement process. The local defense is "sealing" data to trusted measurements. The remote defense is "attestation" or "quote", getting signed measurements and deciding whether to trust them. The TPM main specification (design principles) discusses measurements,> reporting, attestation, and so on. The "TCG PC Client Specific Implementation Specification For Conventional BIOS" is specific to the PC platform (there are specifications for mobile devices, printers, storage, etc.) but section 1.2 has a good discussion of the concepts. https://www.trustedcomputinggroup.org/home (Feel free to email me privately if this is becoming off topic for the mailing list.) --
| debian developer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Greg Kroah-Hartman | [PATCH 002/196] Chinese: rephrase English introduction in HOWTO |
| Jan Engelhardt | intel iommu (Re: -mm merge plans for 2.6.23) |
| Vladislav Bolkhovitin | Re: Integration of SCST in the mainstream Linux kernel |
git: | |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Gerrit Renker | [PATCH 15/37] dccp: Set per-connection CCIDs via socket options |
| Antonio Almeida | HTB accuracy for high speed |
| David Miller | [GIT]: Networking |
