Re: [p2p-hackers] Verifying Claims of Full-Disk Encryption in Hard Drive Firmware

9 Nov
9 Nov
5:17 a.m.
New subject: [p2p-hackers] Verifying Claims of Full-Disk Encryption in Hard Drive Firmware
Eugen Leitl <eugen@leitl.org> quotes Tom Ritter <tom@ritter.vg>:
Without wanting to sound too facetious, and mostly out of curiosity, what does FIPS 140 have to do with the threat modelling you've done? It doesn't address the vast majority of the stuff you've listed, so the threat-modelling is kind of a non-sequitur to "starting with FIPS 140". If you wanted to deal with this through a certification process you'd have to go with something like the CC (and an appropriate PP), assuming the sheer suckage of working with the CC doesn't tear a hole in the fabric of space-time in the process. Peter.
4975
Age (days ago)
4975
Last active (days ago)
1 comments
2 participants
participants (2)
-
Eugen Leitl
-
Peter Gutmann