Showing posts with label UEFI Shell. Show all posts
Showing posts with label UEFI Shell. Show all posts

Saturday, August 26, 2023

Co-authors then and now

 So I mentioned in my last blog that I could always talk about https://www.cisa.gov/news-events/news/call-action-bolster-uefi-cybersecurity-now.  Well, it turns out the UEFI Forum posted a pretty good read this week on the topic of UEFI and ecosystems, namely the top posting at https://uefi.org/learning_center/papers, in the document https://uefi.org/sites/default/files/resources/Decoding%20UEFI%20Firmware-Aug24-2023-Final_v2_0.pdf


The authors are folks I have enjoyed working with across various teams and decades. Some of the collaborations have spanned companies and different venues, such as papers, books, and presentations. 

To begin, I think Dong Wei https://www.crunchbase.com/person/dong-wei and I first appeared in print together with the original Beyond BIOS book in 2006, 



with Dong providing the forward

Next up was the 2008 UEFI Shell book


with preface



This 2008 book was followed with a 2009 whitepaper https://uefi.org/sites/default/files/resources/A_Tale_of_Two_Standards_0.pdf


I was a bit excited about IPV6 at the time as I was in the throes of getting https://datatracker.ietf.org/doc/html/rfc5970 through an unfamiliar standards body, namely the IETF.

Next was the presentation circuit with 2010 presentation in Shanghai


and San Francisco

Shanghai https://en.sjtu.edu.cn/ was nice to visit since so many of my long-time collaborators in our Intel Shanghai office, like Jiewen Yao, are alumni of this institution.

Then the 2nd edition of the Beyond BIOS book in 2010 came next


with Dong reprising his preface-writing skills with

Finally a couple of proposals for UEFI and RISC-V for the 2015 


and 2016 conference


were created with Dong. 

All of the collaborations before 2023 with Dong were when he was at HP (and then HPe after the split). 

And now in 2023 with Dong as ARM Ltd's chief standards architect and an ARM Fellow.  The total collaboration instances makes nine per my accounting.

Speaking of 'chief's', Insyde Software's Chief Technology Officer  (CTO) https://www.insyde.com/company/executive-management was another rich engagement.


The collaborations with Tim commenced in 2008 with the UEFI Shell book first edition


and an IDF presentation that same year presented at both the Taipei and Shanghai events


The Intel Developer Forum (IDF) was an annual event in California show-casing various Intel and industry advancements. Today I believe it has been superseded by venues such as Intel Ignite. 

I co-authored an Intel Technology Journal https://www.intel.com/content/dam/www/public/us/en/documents/research/2011-vol15-iss-1-intel-technology-journal.pdf article with Tim in 2011



Tim and I also jointly presented in 2011 at the Intel Developer Forum in San Francisco


All of the preceding presentations were done when Tim was with Phoenix Technology. Tim had joined Insyde when the joint book-authorship was reprised with the 2nd edition of the UEFI Shell book in 2017 https://www.degruyter.com/document/doi/10.1515/9781501505751/html



Tim was also gracious to serve as the technical reviewer for Firmware Security https://link.springer.com/book/10.1007/978-1-4842-6106-4 book in 2020 




These collaborations with Tim look like they sum to seven.

Tim and Dong have made seminal contributions to the ACPI, UEFI, and PI specifications. In fact as late as 2010 Tim was the chair of the UEFI Security Subteam (started with the UEFI Forum in 2010). From the 2nd edition of Beyond BIOS

 


 

before I took over that subteam. In fact I drafted this recent overview of the UEFI Forum Subteam's

From there you can see the various working groups.  I believe Dong and Mark Doran co-chair ASWG, Mark PIWG, Mark USWG, etc. Among the co-authors of this blog's showcase paper. Dick Wilkins is the Phoenix Board of Directors (BOD) rep, Bill Keown for Lenovo, and Dong for ARM, respectively. Co-author Brian Mullen chairs the new Software Bill of Material (SBOM) subteam, Dick chairs the UEFI Security Response Team, and I chair the UEFI Security Subteam. I elided subteams like graphics, configuration, and networking from the infographic as they are mostly dormant these last few years. I created the above image derived from earlier https://uefi.org/sites/default/files/resources/UEFI_Plugfest_VZimmer_Fall_2016.pdf as a companion to another mutation (from image in https://embeddedcomputing.com/technology/security/software-security/understanding-uefi-firmware-update-and-its-vital-role-in-keeping-computing-systems-secure) I crafted to give folks an idea about how SBOM's impact EDKII-style system firmware, viz.,



Well, that's it for today.  This is my small gesture to leave a bit of history since a lot of this system firmware work I've done will be unlikely to land in more esteemed repos like http://www.bitsavers.org/bits/ and is surely aging off the internet. I even recall that a request was required to get the Intel Technology Journal back on intel.com. Regrettably the same audible wasn't called for other publications like "Technology at Intel" magazine or most back-dated Intel Developer Forum prezos. An example of what gets lost on the internet can be found in citation curation sites like https://dblp.uni-trier.de/pid/34/5641.html; here I only see Tim mentioned once, for example.




Sunday, January 1, 2017

Saying good bye to 2016

I meant to do a final blog of '16 but I instead opted to catch the fireworks at the Seattle Space Needle



I like the end of the year as it hosts the Chaos Communications Conference (33c3). I recall seeing Trammell Hudson's Thunderstrike 2 https://media.ccc.de/v/32c3-7236-thunderstrike_2 over the '15 holiday, and for this '16 holiday I watched his talk on Heads, variously described in
http://hackaday.com/2016/12/29/33c3-if-you-cant-trust-your-computer-who-can-you-trust/
https://trmm.net/heads_33c3
https://www.youtube.com/watch?v=UqxRPLfrpfA

I like Trammell's threat model write up at https://trmm.net/Heads_threat_mode, too. Today we only have the higher level http://www.uefi.org/sites/default/files/resources/Intel-UEFI-ThreatModel.pdf.

It was interesting to see his mention of Intel (R) FSP and also reference our work on pre-OS DMA protection https://github.com/vincentjzimmer/Documents/blob/master/A_Tour_Beyond_BIOS_Using_Intel_VT-d_for_DMA_Protection.pdf.

Another talk of interest for the pre-OS was the review of porting UEFI Secure Boot for virtual machines https://media.ccc.de/v/33c3-8142-virtual_secure_boot. This entails the Open Virtual Machine Format (OVMF) http://www.tianocore.org/ovmf/ variant of EDKII that executes upon QEMU and is used as the guest firmware in projects like KVM, Virtualbox, etc.

The latter talk included a reference to the EDKII lock box https://www.kraxel.org/slides/virtual-secure-boot/#sb-virtual
work https://github.com/vincentjzimmer/Documents/blob/master/A_Tour_Beyond_BIOS_Implementing_S3_resume_with_EDKII_V2.pdf and emulating the full System Management Mode (SMM) infrastructure. The addition of more of the SMM infrastructure in https://github.com/tianocore/edk2/tree/master/UefiCpuPkg was positively mentioned, too.

Speaking of security and 33c3, an interesting read about researchers and industry was posted to
http://laforge.gnumonks.org/blog/20161206-it_security_culture_telecoms/. As long as the flaws are responsibly disclosed such that the conference presentations aren't zero-day events, I cannot argue with their sentiment.

One common element discussed in Heads and the Virtual Secure Boot topics entailed availability of full platforms. In that area there is great progress in having a set of full EDKII platform code in source that works with an Intel(R) FSP for the embedded Apollo Lake (APL) https://ark.intel.com/products/codename/80644/Apollo-Lake#@Embedded SOC (formerly known as "Broxton") in the repository https://github.com/tianocore/edk2-platforms/tree/devel-MinnowBoard3/.

Regarding security and treatment of EDKII https://github.com/tianocore/edk2 issues, we have moved our advisory update to gitbook from the former two PDF postings
https://www.gitbook.com/book/edk2-docs/security-advisory/details. These recent postings represent fixes that honored the industry request for six month embargo of the project updates. Going forward we'd like to auto-generate the advisory from Bugzilla https://github.com/tianocore/tianocore.github.io/wiki/Reporting-Security-Issues, but for now the document is manually curated. There have also been discussions of moving from the advisory document issue enumeration to things like CVE's https://cve.mitre.org/ which is an investigation in progress, too.

Moving into 2017, maybe I'll catch up to George Westinghouse's https://en.wikipedia.org/wiki/George_Westinghouse number of issued US Patents. I left 2016 with 354 issued, whereas George has 361 https://en.wikipedia.org/wiki/List_of_prolific_inventors.

2017 should also feature an update to a couple of UEFI books, including Beyond BIOS
https://www.degruyter.com/view/product/484468 and Harnessing the UEFI Shell
https://www.degruyter.com/view/product/484477. Beyond BIOS was originally published in 2006, so this update will mark over a decade since its first appearance.

It has been an interesting run on this project, with over 17 years on the EFI team and nearly 20 years at Intel. I look forward to what the next wave of technology will bring in '17 and beyond.