Someone wrote in [personal profile] mjg59 2011-11-17 06:49 pm (UTC)

what about DRTM?

You seem to be describing Static Root for Trust Measurement (SRTM) where each part of the boot sequence verifies the integrity of the next phase. Afaik if you use Dynamic Root for Trust Measurement (DRTM) then a bug in a boot loader is not enough to compromise the system. Qubes development blog has somewhat related posts

http://theinvisiblethings.blogspot.com/2010/04/remotely-attacking-network-cards-or-why.html
http://theinvisiblethings.blogspot.com/2009/01/why-do-i-miss-microsoft-bitlocker.html

You might also want to read the description of the x86 SENTER/SINIT (secure init) instruction.

Post a comment in response:

If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org