File:Replace Your Exploit-Ridden Firmware with Linux - Ronald Minnich, Google.webm

Original file(WebM audio/video file, VP9/Opus, length 38 min 2 s, 1,280 × 720 pixels, 515 kbps overall, file size: 140.08 MB)

Captions

Captions

Add a one-line explanation of what this file represents

Summary edit

Description
English: Replace Your Exploit-Ridden Firmware with Linux - Ronald Minnich, Google

With the WikiLeaks release of the vault7 material, the security of the UEFI (Unified Extensible Firmware Interface) firmware used in most PCs and laptops is once again a concern. UEFI is a proprietary and closed-source operating system, with a codebase almost as large as the Linux kernel, that runs when the system is powered on and continues to run after it boots the OS (hence its designation as a “Ring -2 hypervisor"). It is a great place to hide exploits since it never stops running, and these exploits are undetectable by kernels and programs.

Our answer to this is NERF (Non-Extensible Reduced Firmware), an open source software system developed at Google to replace almost all of UEFI firmware with a tiny Linux kernel and initramfs. The initramfs file system contains an init and command line utilities from the u-root project (http://u-root.tk/), which are written in the Go language.

About Ronald G. Minnich

Ron Minnich is a Software Engineer at Google. He has contributed to many open source projects in the last several decades, including the Linux kernel (9p file system); the FreeBSD kernel (rfork); and Plan 9 (many different areas). He directed the team that ported Plan 9 to the Blue Gene supercomputers. He invented LinuxBIOS (now called coreboot) in 1999. He is one of the core contributors to the Harvey operating system. His most recent Linux Foundation talk was on how to build your own signed version of ChromeOS and resign your Chromebook with your personal keys in 2016.

Replace Your Exploit-Ridden Firmware with Linux - Ronald Minnich, Google

With the WikiLeaks release of the vault7 material, the security of the UEFI (Unified Extensible Firmware Interface) firmware used in most PCs and laptops is once again a concern. UEFI is a proprietary and closed-source operating system, with a codebase almost as large as the Linux kernel, that runs when the system is powered on and continues to run after it boots the OS (hence its designation as a “Ring -2 hypervisor"). It is a great place to hide exploits since it never stops running, and these exploits are undetectable by kernels and programs.

Our answer to this is NERF (Non-Extensible Reduced Firmware), an open source software system developed at Google to replace almost all of UEFI firmware with a tiny Linux kernel and initramfs. The initramfs file system contains an init and command line utilities from the u-root project (http://u-root.tk/​), which are written in the Go language.

About Ronald G. Minnich

Ron Minnich is a Software Engineer at Google. He has contributed to many open source projects in the last several decades, including the Linux kernel (9p file system); the FreeBSD kernel (rfork); and Plan 9 (many different areas). He directed the team that ported Plan 9 to the Blue Gene supercomputers. He invented LinuxBIOS (now called coreboot) in 1999. He is one of the core contributors to the Harvey operating system. His most recent Linux Foundation talk was on how to build your own signed version of ChromeOS and resign your Chromebook with your personal keys in 2016.
Date
Source YouTube: Replace Your Exploit-Ridden Firmware with Linux - Ronald Minnich, Google – View/save archived versions on archive.org and archive.today
Author The Linux Foundation

Licensing edit

This video, screenshot or audio excerpt was originally uploaded on YouTube under a CC license.
Their website states: "YouTube allows users to mark their videos with a Creative Commons CC BY license."
To the uploader: You must provide a link (URL) to the original file and the authorship information if available.
w:en:Creative Commons
attribution
This file is licensed under the Creative Commons Attribution 3.0 Unported license.
You are free:
  • to share – to copy, distribute and transmit the work
  • to remix – to adapt the work
Under the following conditions:
  • attribution – You must give appropriate credit, provide a link to the license, and indicate if changes were made. You may do so in any reasonable manner, but not in any way that suggests the licensor endorses you or your use.
YouTube logo This file, which was originally posted to YouTube: Replace Your Exploit-Ridden Firmware with Linux - Ronald Minnich, Google, was reviewed on 7 March 2021 by the automatic software YouTubeReviewBot, which confirmed that this video was available there under the stated Creative Commons license on that date. This file should not be deleted if the license has changed in the meantime. The Creative Commons license is irrevocable.

The bot only checks for the license, human review is still required to check if the video is a derivative work, has freedom of panorama related issues and other copyright problems that might be present in the video. Visit licensing for more information. If you are a license reviewer, you can review this file by manually appending |reviewer={{subst:REVISIONUSER}} to this template.

Creative Commons logo

File history

Click on a date/time to view the file as it appeared at that time.

Date/TimeThumbnailDimensionsUserComment
current07:16, 7 March 202138 min 2 s, 1,280 × 720 (140.08 MB)Acagastya (talk | contribs)Imported media from uploads:56cb2622-7f0b-11eb-8f43-0a7fb64cb320

The following page uses this file:

Transcode status

Update transcode status
Format Bitrate Download Status Encode time
VP9 720P 361 kbps Completed 08:03, 7 March 2021 43 min 32 s
Streaming 720p (VP9) Not ready Unknown status
VP9 480P 233 kbps Completed 07:55, 7 March 2021 35 min 26 s
Streaming 480p (VP9) Not ready Unknown status
VP9 360P 170 kbps Completed 07:40, 7 March 2021 24 min 15 s
Streaming 360p (VP9) Not ready Unknown status
VP9 240P 137 kbps Completed 07:35, 7 March 2021 19 min 19 s
Streaming 240p (VP9) 57 kbps Completed 22:58, 16 December 2023 3.0 s
WebM 360P 342 kbps Completed 07:37, 7 March 2021 17 min 15 s
Streaming 144p (MJPEG) 1 Mbps Completed 01:36, 19 November 2023 1 min 17 s
Stereo (Opus) 80 kbps Completed 08:42, 23 November 2023 40 s
Stereo (MP3) 128 kbps Completed 01:36, 19 November 2023 51 s

Metadata