IPMI - because ACPI and UEFI weren't terrifying enough
Matthew Garrett
http://lca2015.linux.org.au/schedule/30130/view_talk
ACPI was dreadful and scary, and it's still scary but at least it mostly works now. UEFI jeopardised the interests of our entire tribe, but we got through it. How could any other four letter specification worry us?
Meet IPMI - the Intelligent Platform Management Interface. A protocol that allows admins to power machines on and off remotely. A protocol that permits remote querying and reporting of hardware errors, fan speeds, temperatures and more. A protocol so poorly designed that it explicitly defines passwordless authentication. A protocol that's generally implemented by gluing a small insecure embedded Linux device to your server motherboards. A protocol implemented by people who don't understand the importance of avoiding leaking bits of the heap in network packets. A protocol that's frequently exposed to the public internet. A protocol that's… well. You get the idea.
This presentation will cover the IPMI protocol and its potential uses for good, along with a deep, dark, depressing discussion of its despair-inducing failings at both the protocol and implementation levels. You'll laugh. You'll cry. You'll never trust your servers again.
Видео IPMI - because ACPI and UEFI weren't terrifying enough канала Linux.conf.au 2015 -- Auckland, New Zealand
http://lca2015.linux.org.au/schedule/30130/view_talk
ACPI was dreadful and scary, and it's still scary but at least it mostly works now. UEFI jeopardised the interests of our entire tribe, but we got through it. How could any other four letter specification worry us?
Meet IPMI - the Intelligent Platform Management Interface. A protocol that allows admins to power machines on and off remotely. A protocol that permits remote querying and reporting of hardware errors, fan speeds, temperatures and more. A protocol so poorly designed that it explicitly defines passwordless authentication. A protocol that's generally implemented by gluing a small insecure embedded Linux device to your server motherboards. A protocol implemented by people who don't understand the importance of avoiding leaking bits of the heap in network packets. A protocol that's frequently exposed to the public internet. A protocol that's… well. You get the idea.
This presentation will cover the IPMI protocol and its potential uses for good, along with a deep, dark, depressing discussion of its despair-inducing failings at both the protocol and implementation levels. You'll laugh. You'll cry. You'll never trust your servers again.
Видео IPMI - because ACPI and UEFI weren't terrifying enough канала Linux.conf.au 2015 -- Auckland, New Zealand
Показать
Комментарии отсутствуют
Информация о видео
16 января 2015 г. 16:55:20
00:47:36
Другие видео канала
![Firmware security, why it matters and how you can have it](https://i.ytimg.com/vi/gP_9sUfpW_o/default.jpg)
![Kernel Recipes 2015 - Representing device-tree peripherals in ACPI - by David Woodhouse](https://i.ytimg.com/vi/p7MoTngjMcI/default.jpg)
![intro to freenas](https://i.ytimg.com/vi/jcrxG6aDAa8/default.jpg)
![Keynote (HD 720p): Linus Torvalds](https://i.ytimg.com/vi/Hw4ihJr82PA/default.jpg)
![ASRock IPMI Overview With Wendell (Intelligent Platform Management Interface)](https://i.ytimg.com/vi/S1Q1-X4pSOg/default.jpg)
![See what your computer is doing with Ftrace utilities](https://i.ytimg.com/vi/68osT1soAPM/default.jpg)
![Apathy and Arsenic: a Victorian Era lesson on fighting the surveillance state](https://i.ytimg.com/vi/egi8Lm5W3FY/default.jpg)
!["Write a single library to handle all input devices, it'll be easy" they said...](https://i.ytimg.com/vi/HllUoT_WE7Y/default.jpg)
!["Keynote: Drop Your Tools – Does Expertise have a Dark Side?" - Dr Sean Brady (LCA 2020)](https://i.ytimg.com/vi/Yv4tI6939q0/default.jpg)
![Charles Schwab Trading Platform Web Tutorial](https://i.ytimg.com/vi/CZsiRomcUeE/default.jpg)
![Open-ZFS Bootcamp](https://i.ytimg.com/vi/mLbtJQmfumI/default.jpg)
![systemd - The Good Parts](https://i.ytimg.com/vi/r_haLf5mWhE/default.jpg)
![Standalone ECU / EFI Tuning Basics](https://i.ytimg.com/vi/u_j3Ov0JmDs/default.jpg)
![Comparing HBA IT mode SAS controllers](https://i.ytimg.com/vi/PeFJtjVvGyc/default.jpg)
![Home Networking: 100TB 10Gbit Server - ZFS considerations (Performance, RAIDz vs RAID and Mirrors)](https://i.ytimg.com/vi/GuUh3bkzaKE/default.jpg)
![[ENG] Andy Shevchenko (Intel): ACPI from scratch: U-Boot implementation / #LinuxPiter](https://i.ytimg.com/vi/46JmzxVLxFQ/default.jpg)
![before Keynote: Linus Torvalds (Bdale happy birthday)](https://i.ytimg.com/vi/Z7c-T0e080M/default.jpg)
![Keeping the Balance: loadbalancing demystified](https://i.ytimg.com/vi/FC0DARpayhw/default.jpg)
![Features of Supermicro IPMI](https://i.ytimg.com/vi/Q2WLd3jZDSM/default.jpg)
![Side-event "After Snowden: using law and technology to counter snooping"](https://i.ytimg.com/vi/OY5zu7u5Ucs/default.jpg)