[HN Gopher] Illuminating the Security Issues Surrounding Lights-...
       ___________________________________________________________________
        
       Illuminating the Security Issues Surrounding Lights-Out Server
       Management (2013) [pdf]
        
       Author : walterbell
       Score  : 10 points
       Date   : 2022-05-15 06:42 UTC (1 days ago)
        
 (HTM) web link (www.usenix.org)
 (TXT) w3m dump (www.usenix.org)
        
       | comboy wrote:
       | IDRAC still uses non-ssl connection for fetching upgrades by
       | default. They all seem so bad on many levels regarding security
       | without even diving deep.
       | 
       | I hope safe virtualization (where host can't access guest stuff)
       | become a standard for hardware, but it still feels backward.
        
         | yjftsjthsd-h wrote:
         | Any chance the updates are signed (w/ PGP or such)? There are
         | ways to make non-ssl safe-ish, and I can kind of accept not
         | wanting a system that depends on an accurate clock and current
         | root certs.
        
           | pixl97 wrote:
           | Imagine the current scenario.
           | 
           | Version 1: Secure, currently in use.
           | 
           | Version 2: Insecure. Known RCE.
           | 
           | Version 3: Secure.
           | 
           | Version 2 in this case is a signed update that is valid from
           | the vendor, but adds a remote exploit that the attacker
           | performing the MITM can then exploit.
        
             | yjftsjthsd-h wrote:
             | Fair point; I suppose I should have said saf _er_ ; GPG
             | gives you authenticity with lower requirements, but is
             | generally inferior to HTTPS.
        
       ___________________________________________________________________
       (page generated 2022-05-16 23:01 UTC)