Skip to main content

Showing 1–1 of 1 results for author: Mandvekar, L

Searching in archive cs. Search in all archives.
.
  1. arXiv:1202.5282  [pdf, ps, other

    cs.CR cs.OS

    How to Bypass Verified Boot Security in Chromium OS

    Authors: Mohammad Iftekhar Husain, Lokesh Mandvekar, Chunming Qiao, Ramalingam Sridhar

    Abstract: Verified boot is an interesting feature of Chromium OS that supposedly can detect any modification in the root file system (rootfs) by a dedicated adversary. However, by exploiting a design flaw in verified boot, we show that an adversary can replace the original rootfs by a malicious rootfs containing exploits such as a spyware or keylogger and still pass the verified boot process. The exploit is… ▽ More

    Submitted 2 June, 2012; v1 submitted 23 February, 2012; originally announced February 2012.

    Comments: Update information about Chromium OS. Added new and advanced exploits. Added mitigation techniques and evaluation