All of lore.kernel.org
 help / color / mirror / Atom feed
From: Vernon Mauery <vernon.mauery@linux.intel.com>
To: Stewart Smith <stewart@linux.ibm.com>
Cc: Nancy Yuen <yuenn@google.com>,
	OpenBMC Maillist <openbmc@lists.ozlabs.org>
Subject: Re: OpenBMC Security Working Group Kick Off
Date: Thu, 31 May 2018 12:53:48 -0700	[thread overview]
Message-ID: <20180531195348.GG105329@mauery> (raw)
In-Reply-To: <87efhs43uo.fsf@linux.vnet.ibm.com>

On 31-May-2018 06:38 PM, Stewart Smith wrote:
>Nancy Yuen <yuenn@google.com> writes:
>> The OpenBMC Security Work Group kick off meeting is scheduled for Thurs May
>> 31, 9AM PDT.  This first meeting is by invite only.  Please email me if you
>> are interested in participating in this working group.
>
>Would topics like "security of the BMC from a hostile host" be part of
>this?

I would vote yes. From a platform architecture, while the pre-boot 
communications from the Host might be more trusted, after the OS boots, 
the host should be considered hostile.

>A design of OpenPOWER systems is that the BMC and the Host don't have to
>trust each other, and this should extend to a host that's hostile
>towards the BMC.

I agree. This is just a plain good design choice. :)

--Vernon

>I'd be surprised if we didn't find bugs in both mboxd and host ipmi if
>we started fuzzing those interfaces.
>
>-- 
>Stewart Smith
>OPAL Architect, IBM.
>

  reply	other threads:[~2018-05-31 19:54 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-05-30 21:04 OpenBMC Security Working Group Kick Off Nancy Yuen
2018-05-31  8:38 ` Stewart Smith
2018-05-31 19:53   ` Vernon Mauery [this message]
2018-06-01  0:38   ` Andrew Jeffery
2018-06-06 22:35     ` Nancy Yuen
2018-06-07  2:44       ` Andrew Jeffery

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20180531195348.GG105329@mauery \
    --to=vernon.mauery@linux.intel.com \
    --cc=openbmc@lists.ozlabs.org \
    --cc=stewart@linux.ibm.com \
    --cc=yuenn@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.