Showing posts with label Toorcamp. Show all posts
Showing posts with label Toorcamp. Show all posts

Friday, August 15, 2014

ToorCamp redux, Upcoming IDF 2014

To lead off today, I was lucky to have the opportunity to speak at ToorCamp this summer, with my talk titled “Secure boot, network boot, verified boot, oh my” http://toorcamp.toorcon.net/talks/#16 and material posted to https://docs.google.com/file/d/0BxgB4JDywk3MdnRsbnh6NW9rYU0/edit
I especially liked my quotation

A reminder from the KGB school of cipher security: “You never attack the standard, you attack the implementation, including the process.” - Grugq



The locale is pretty remote, namely the western-most portion of the US
My talk was on a Thursday and I was swamped at the office, so I ended up making it a 'day trip' from Tacoma to Neah Bay.

Like 2012, the talks were all hosted in the dome

including the couch for chatting with the host

I have to admit that the speaker on bio-hacking and transhumanism didn't convince me to get an RFID injection into my hand this trip.

I gave my talk and followed up with some face to face discussions for a couple hours afterward. Invariably the question of key revocation came up as a question in response to the Secure Boot discussion. Then I scurried to the nearby beach, snapped a photo of the sunset, and then headed back home. Luckily the local tribesman selling smoked salmon hadn't closed up shop, so I picked up a few packages of the same and beat a hasty retreat.

Saying goodbye to the Makah reservation


and the hackers at Hobuck Beach



The next journey is the Intel Developer Forum in San Francisco.  My upcoming talk is “Firmware Flexibility  using Intel Firmware Support Package,” Talk STTS001, Intel Developer Forum, San Francisco, September 11, 2014 https://intel.activeevents.com/sf14/connect/sessionDetail.ww?SESSION_ID=1265 This should provide a deep dive responsive to the https://intel.activeevents.com/sf13/connect/fileDownload/session/DB60155205A8DF5837DA22D0FF90E3A3/SF13_STTS001_100.pdf presentation last year, along with a few other updates on ecosystems and open source. Drop me a line if you're in SF at this time.

On other progress, my issued US Patents continue to climb, albeit slowly. Now that I've crossed the 300 mark (303 this week for US Patent Families and 823 for INPADOC) maybe I'll get to join the list of 'Prolific Inventors' at http://en.wikipedia.org/wiki/List_of_prolific_inventors. I am curious how to site confirms the assertion: "However, this table currently has an arbitrary cut-off limit for inclusion of 300 patent families. This is purely for practical reasons – there are 81 inventors throughout history with more than 300 utility patent families, but tens of thousands of inventors with more than 15 patents."  Hmmm.

This summer has also witnessed a flurry of presentations on attacks against UEFI implementations, including http://www.mitre.org/sites/default/files/publications/14-2221-extreme-escalation-presentation.pdf. This reminds me of the importance of the Grugq quote above on 'implementation' and underscores the value of work like Chipsec https://github.com/chipsec/chipsec I mentioned in http://www.uefi.org/sites/default/files/resources/2014_UEFI_Plugfest_04_Intel.pdf and other developer guidance, such as 'best practices' in pages 34-35 of http://www-inst.eecs.berkeley.edu/~cs194-24/sp13/hand-outs/SF09_EFIS001_UEFI_PI_TCG_White_Paper.pdf, But there are many additional things we can do with respect to testing, guidance, and instances of best-practices on http://tianocore.sourceforge.net/wiki/EDK2. Speaking of edk2 and security practices, I'm happy to see a reference implementation of a signed capsule update implementation, including the https://svn.code.sf.net/p/edk2/code/trunk/edk2/SecurityPkg/Library/DxeRsa2048Sha256GuidedSectionExtractLib/ support code.

Another exciting open source action is the release of seL4 kernel http://sel4.systems/ and the Isabelle proofs. I mentioned this effort in http://vzimmer.blogspot.com/2013/12/better-living-through-tools.html and since that publication https://github.com/seL4/seL4 has gone live. Gernot and the NICTA guys are impressive. I was happy to see my ex-NICTA collaborator Leonid posted our driver synthesis paper http://www.nicta.com.au/pub?doc=7690 to NICTA's website http://ssrg.nicta.com.au/projects/TS/drivers/synthesis/ 

Regarding the latter paper, this is as close as I can get to a refereed conference, it would seem, as Mike Rothman and I were bounced from LISA '14. We posted the rejected manuscript at https://uefidk.com/sites/default/files/resources/uefi-manageability-security-white-paper.pdf.  Since I'm not an academic but an ordinary Joe who has been slogging away in industry for the last 20+ years, I cannot understand the publish-or-perish or other metrics around papers http://blogs.lse.ac.uk/impactofsocialsciences/2014/04/23/academic-papers-citation-rates-remler/ in academia. I see the value of peer review and appreciate the written-word, along with open source, to scale pedagogy and advocacy.  

Social media never ceases to fascinate me.

Pageviews by Countries

Graph of most popular countries among blog viewers
EntryPageviews
Malaysia
2

Pageviews by Browsers

EntryPageviews
Chrome
2 (100%)
Image displaying most popular browsers

Pageviews by Operating Systems

EntryPageviews
Macintosh
2 (100%)
Image displaying most popular platforms

represents the latest access to this blog.  Someone reading this blog while running Google Chrome on a Macintosh in Malaysia.  Fascinating.

Or on Twitter https://twitter.com/vincentzimmer when I get a re-tweet or message from famous mathematicians
 retweeted your Retweet
Jun 28
This is a geometry joke.

Great stuff.

1/7/2015 update -
A friend of mine from Houston just pointed out an update to http://en.wikipedia.org/wiki/List_of_prolific_inventors.
I'm now on the list, and not even the 'bottom-most' entry (and among the youngest who owns up to his/her age).
Vincent Zimmer312 USA8481970-Computer software and firmware[181][182]

Sunday, August 26, 2012

One conference down, one to go....

Back fromToorCamp, 2012.   To get a sense of the event, check out the closing video  http://www.youtube.com/watch?v=Q7IeJ0HGK6o.  Here are a few pictures of the camp I snapped on my phone, including the dome in the distance.

The camp site was right next to the beach, too.   Neah Bay is the northwest-most point of the continental US, so the Pacific Ocean formed the back yard for the talk.



The main dome hosted the various talks.   Here's a closer view, including the podium in the back:
I delivered my talk on firmware security on Thursday afternoon.   A link to my foils for
“UEFI Secure Boot and challenges in platform firmware” can be found at https://docs.google.com/open?id=0BxgB4JDywk3MWnM0WmNXMHBTcm8.   The other talks were a mix of information security and the maker movement leading up to my presentation, so I treated my discussion of firmware security alongside a a review of the UDK2010 open source implementation of UEFI Secure Boot and the user controls enabled via Custom Mode on IA32 machines.   Insightful questions both during the talk and with the researchers afterward.

Other interesting talks included Dan Griffin's discussion on TPM's and UEFI, which largely focused on measured boot from the operating system perspective.  This talk was a shortened version of his DEFCON talk 
https://docs.google.com/file/d/0B7n3jaMQDSNCeDJBd2tnRGIxbDA/edit#.    Dan Kaminsky also spoke about all things security, including weaknesses of random number generators http://dankaminsky.com/2012/08/15/dakarand/.  Other interesting perspectives from DanK included how type safe language are not the security panacea since different machine on the network are written in different languages, so all communications must convert data to strings.  And it is in these strings that attacks, injections, and vulnerabilities occur.   Hearing both Seattle Dan's speak alone was worth the trip.

On top of the great info-sec talks, on Friday I had the opportunity to attend a session by George Dyson http://en.wikipedia.org/wiki/George_Dyson_(science_historian) on Project Orion http://en.wikipedia.org/wiki/Project_Orion_(nuclear_propulsion)



And speak with George afterward.
I was as much inspired by his discussions of Orion, my read of his recent book on the history of the computer http://www.amazon.com/Turings-Cathedral-Origins-Digital-Universe/dp/0375422773, and of course, kayaks http://www.amazon.com/Baidarka-Kayak-George-Dyson/dp/088240315X/ref=sr_1_4?s=books&ie=UTF8&qid=1346014068&sr=1-4.   Regrettably, the only hard copy of a book related to  George I brought along to the camp was the book 'about' George and his father Freeman http://en.wikipedia.org/wiki/Freeman_Dyson
But I asked for an autograph anyway.

Overall, I enjoyed having the opportunity to participate in this type of conference.   The spirit of creation, invention and curiosity was infectious and shared by all.   And the accommodations were quite interesting, too.


Next stop is the Intel Developer Forum in San Francisco on September 10.   I suspect that my hotel will be a little further detached from Mother Nature, though.

Cheers