20-07-2024, 12:48 PM
(20-07-2024, 11:48 AM)ppppenguin Wrote: Could the problem be solved, in principle, by running desktops and other end points with a "bare metal" hypervisor which then boots the required OS? This of course assumes that a bare metal hypervisor is relatively immune to attacks, which may be a risky assumption.
Am I right in thinking that even below BIOS level there's a management processor running on all x86 chips? Something that ordinary mortals never see and can't readily access.
No to the alternative end-point boot. This doesn't get round the TPM issues and is directly contrary to most corporate policies regarding end point security - it opens a whole Pandora's Box of possibilities.
Yes, most modern Intel & AMD processors have embedded management processors (which themselves have been subject to attack).
sıʌǝɹq ɐʇıʌ `ɐƃuol sɹɐ
ʞɔıu
ʞɔıu







