From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mailman by lists.gnu.org with archive (Exim 4.43) id 1KbY6w-00068i-Bi for mharc-grub-devel@gnu.org; Fri, 05 Sep 2008 06:00:14 -0400 Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1KbY6r-00068S-RD for grub-devel@gnu.org; Fri, 05 Sep 2008 06:00:10 -0400 Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1KbY6r-00068G-8H for grub-devel@gnu.org; Fri, 05 Sep 2008 06:00:09 -0400 Received: from [199.232.76.173] (port=51155 helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1KbY6q-00068D-QZ for grub-devel@gnu.org; Fri, 05 Sep 2008 06:00:09 -0400 Received: from aybabtu.com ([69.60.117.155]:50800) by monty-python.gnu.org with esmtps (TLS-1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.60) (envelope-from ) id 1KbY6q-00021W-QT for grub-devel@gnu.org; Fri, 05 Sep 2008 06:00:09 -0400 Received: from [192.168.10.10] (helo=thorin) by aybabtu.com with esmtps (TLS-1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.69) (envelope-from ) id 1KbXwM-0001xV-Iq for grub-devel@gnu.org; Fri, 05 Sep 2008 11:49:21 +0200 Received: from rmh by thorin with local (Exim 4.63) (envelope-from ) id 1KbY53-0001Po-Nu for grub-devel@gnu.org; Fri, 05 Sep 2008 11:58:17 +0200 Date: Fri, 5 Sep 2008 11:58:17 +0200 From: Robert Millan To: The development of GRUB 2 Message-ID: <20080905095817.GB5220@thorin> References: <48BE5DE9.4090302@gmail.com> <20080903103654.GC29762@thorin> <48BE838E.9090204@gmail.com> <48BEC078.7030006@nic.fi> <48BEC6AD.5040305@gmail.com> <48BECE1A.1070406@nic.fi> <20080904193714.GE9133@thorin> <48C055D0.5010402@gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <48C055D0.5010402@gmail.com> Organization: free as in freedom X-Message-Flag: Worried about Outlook viruses? Switch to Thunderbird! www.mozilla.com/thunderbird X-Debbugs-No-Ack: true User-Agent: Mutt/1.5.13 (2006-08-11) X-detected-kernel: by monty-python.gnu.org: Genre and OS details not recognized. Subject: Re: [RFC] Boot parameters and geometrical stability X-BeenThere: grub-devel@gnu.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: The development of GRUB 2 List-Id: The development of GRUB 2 List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 05 Sep 2008 10:00:11 -0000 On Thu, Sep 04, 2008 at 11:40:32PM +0200, phcoder wrote: > Robert Millan wrote: > > On Wed, Sep 03, 2008 at 08:49:14PM +0300, Vesa Jääskeläinen wrote: > >> Possibilites are there, but basically they are limited to something like: > >> > >> (ata0) (pci-X-Y-Z:ata0) (usb-X-Y:scsi0) (pci-X-Y-Z:scsi0) > > > > I think this is overkill, and doesn't really address the root of the problem. > > > > The real security problem here is whether the executable code you're loading is > > trusted, NOT where you load the code from. > If the code is loaded from the same place as we do then we can trust it > (if attacker could modify the code, he could also modify us) Right. I was assuming you mean when code is loaded from different places. Having untrusted code perform the verification of other untrusted code is useless, of course. -- Robert Millan The DRM opt-in fallacy: "Your data belongs to us. We will decide when (and how) you may access your data; but nobody's threatening your freedom: we still allow you to remove your data and not access it at all."