Copernicus: Question your assumptions about BIOS security

Abstract

Discussion of how Copernicus could be used for enterprise-wide assessment of BIOS vulnerabilities, and integrity checking BIOSes to look for the presence of malicious implants. (In the ToorCon form, it was part of an extended 90 minute talk, including some BIOS Chronomancy material.)

Publication
In MTEM (Jul) 2013, DCISE TechEx 2013, ToorCon (Oct) 2013

Unfortunately the slides for this are no longer publicly available, due to the first two venues being private by-invite-only defense industrial base meetings, and ToorCon not keeping archived presentations for 2013.

Xeno Kovah
Xeno Kovah
Dark Mentor Level X

Hacking firmware like it’s no big deal.