openbmc.lists.ozlabs.org archive mirror
 help / color / mirror / Atom feed
* OpenBMC Security Working Group Kick Off
@ 2018-05-30 21:04 Nancy Yuen
  2018-05-31  8:38 ` Stewart Smith
  0 siblings, 1 reply; 6+ messages in thread
From: Nancy Yuen @ 2018-05-30 21:04 UTC (permalink / raw)
  To: OpenBMC Maillist

[-- Attachment #1: Type: text/plain, Size: 1127 bytes --]

The OpenBMC Security Work Group kick off meeting is scheduled for Thurs May
31, 9AM PDT.  This first meeting is by invite only.  Please email me if you
are interested in participating in this working group.

In the future we will have public meetings open to the community.  But the
nature of security is such that some more restricted meetings will be
necessary.

The current agenda is below.  The group will send an update with meeting
notes after the meeting tomorrow.

Current agenda <https://goo.gl/forms/QS8j4j6mnWGYYNDj2>:

   - Introduction round table: what you're interested in and why
   - Joseph Reynolds: OpenBMC security documentation project
   https://gerrit.openbmc-project.xyz/#/c/10443/
   <https://gerrit.openbmc-project.xyz/#/c/10443/>
   - Ben Stoltz: CC as it applies to design and implementation phases.
   Separation of policy and mechanism in BMC lifecycle, including product
   lifecycle manufacture, provisioning, deployment, operations and
   maintenance, recovery, and disposition. E.g. repairs: {Low-/Med-/High-
   touch} x {manual-/automated-self-/automated-assisted- repair}


----------
Nancy

[-- Attachment #2: Type: text/html, Size: 1635 bytes --]

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: OpenBMC Security Working Group Kick Off
  2018-05-30 21:04 OpenBMC Security Working Group Kick Off Nancy Yuen
@ 2018-05-31  8:38 ` Stewart Smith
  2018-05-31 19:53   ` Vernon Mauery
  2018-06-01  0:38   ` Andrew Jeffery
  0 siblings, 2 replies; 6+ messages in thread
From: Stewart Smith @ 2018-05-31  8:38 UTC (permalink / raw)
  To: Nancy Yuen, OpenBMC Maillist

Nancy Yuen <yuenn@google.com> writes:
> The OpenBMC Security Work Group kick off meeting is scheduled for Thurs May
> 31, 9AM PDT.  This first meeting is by invite only.  Please email me if you
> are interested in participating in this working group.

Would topics like "security of the BMC from a hostile host" be part of
this?

A design of OpenPOWER systems is that the BMC and the Host don't have to
trust each other, and this should extend to a host that's hostile
towards the BMC.

I'd be surprised if we didn't find bugs in both mboxd and host ipmi if
we started fuzzing those interfaces.

-- 
Stewart Smith
OPAL Architect, IBM.

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: OpenBMC Security Working Group Kick Off
  2018-05-31  8:38 ` Stewart Smith
@ 2018-05-31 19:53   ` Vernon Mauery
  2018-06-01  0:38   ` Andrew Jeffery
  1 sibling, 0 replies; 6+ messages in thread
From: Vernon Mauery @ 2018-05-31 19:53 UTC (permalink / raw)
  To: Stewart Smith; +Cc: Nancy Yuen, OpenBMC Maillist

On 31-May-2018 06:38 PM, Stewart Smith wrote:
>Nancy Yuen <yuenn@google.com> writes:
>> The OpenBMC Security Work Group kick off meeting is scheduled for Thurs May
>> 31, 9AM PDT.  This first meeting is by invite only.  Please email me if you
>> are interested in participating in this working group.
>
>Would topics like "security of the BMC from a hostile host" be part of
>this?

I would vote yes. From a platform architecture, while the pre-boot 
communications from the Host might be more trusted, after the OS boots, 
the host should be considered hostile.

>A design of OpenPOWER systems is that the BMC and the Host don't have to
>trust each other, and this should extend to a host that's hostile
>towards the BMC.

I agree. This is just a plain good design choice. :)

--Vernon

>I'd be surprised if we didn't find bugs in both mboxd and host ipmi if
>we started fuzzing those interfaces.
>
>-- 
>Stewart Smith
>OPAL Architect, IBM.
>

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: OpenBMC Security Working Group Kick Off
  2018-05-31  8:38 ` Stewart Smith
  2018-05-31 19:53   ` Vernon Mauery
@ 2018-06-01  0:38   ` Andrew Jeffery
  2018-06-06 22:35     ` Nancy Yuen
  1 sibling, 1 reply; 6+ messages in thread
From: Andrew Jeffery @ 2018-06-01  0:38 UTC (permalink / raw)
  To: Stewart Smith, Nancy Yuen, OpenBMC Maillist

On Thu, 31 May 2018, at 18:08, Stewart Smith wrote:
> Nancy Yuen <yuenn@google.com> writes:
> > The OpenBMC Security Work Group kick off meeting is scheduled for Thurs May
> > 31, 9AM PDT.  This first meeting is by invite only.  Please email me if you
> > are interested in participating in this working group.
> 
> Would topics like "security of the BMC from a hostile host" be part of
> this?

I vote yes, and I'm picking up the work to shut down some of the obvious holes again now, at least from an OpenPOWER perspective.

> 
> A design of OpenPOWER systems is that the BMC and the Host don't have to
> trust each other, and this should extend to a host that's hostile
> towards the BMC.
> 
> I'd be surprised if we didn't find bugs in both mboxd and host ipmi if
> we started fuzzing those interfaces.

I've have a neglected branch floating around that adds an AFL harness for mboxd. I should start hacking on that again :)

Andrew

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: OpenBMC Security Working Group Kick Off
  2018-06-01  0:38   ` Andrew Jeffery
@ 2018-06-06 22:35     ` Nancy Yuen
  2018-06-07  2:44       ` Andrew Jeffery
  0 siblings, 1 reply; 6+ messages in thread
From: Nancy Yuen @ 2018-06-06 22:35 UTC (permalink / raw)
  To: Andrew Jeffery; +Cc: Stewart Smith, OpenBMC Maillist

[-- Attachment #1: Type: text/plain, Size: 1184 bytes --]

----------
Nancy

On Thu, May 31, 2018 at 5:38 PM, Andrew Jeffery <andrew@aj.id.au> wrote:

> On Thu, 31 May 2018, at 18:08, Stewart Smith wrote:
> > Nancy Yuen <yuenn@google.com> writes:
> > > The OpenBMC Security Work Group kick off meeting is scheduled for
> Thurs May
> > > 31, 9AM PDT.  This first meeting is by invite only.  Please email me
> if you
> > > are interested in participating in this working group.
> >
> > Would topics like "security of the BMC from a hostile host" be part of
> > this?
>
> I vote yes, and I'm picking up the work to shut down some of the obvious
> holes again now, at least from an OpenPOWER perspective.
>

Definitely it would be a security topic for our platforms.


>
> >
> > A design of OpenPOWER systems is that the BMC and the Host don't have to
> > trust each other, and this should extend to a host that's hostile
> > towards the BMC.
> >
> > I'd be surprised if we didn't find bugs in both mboxd and host ipmi if
> > we started fuzzing those interfaces.
>
> I've have a neglected branch floating around that adds an AFL harness for
> mboxd. I should start hacking on that again :)
>

Maybe for OpenBMC Fix it next week? :D


>
> Andrew
>

[-- Attachment #2: Type: text/html, Size: 2169 bytes --]

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: OpenBMC Security Working Group Kick Off
  2018-06-06 22:35     ` Nancy Yuen
@ 2018-06-07  2:44       ` Andrew Jeffery
  0 siblings, 0 replies; 6+ messages in thread
From: Andrew Jeffery @ 2018-06-07  2:44 UTC (permalink / raw)
  To: Nancy Yuen; +Cc: Stewart Smith, OpenBMC Maillist

> > > A design of OpenPOWER systems is that the BMC and the Host don't have to
> > > trust each other, and this should extend to a host that's hostile
> > > towards the BMC.
> > >
> > > I'd be surprised if we didn't find bugs in both mboxd and host ipmi if
> > > we started fuzzing those interfaces.
> >
> > I have a neglected branch floating around that adds an AFL harness for
> > mboxd. I should start hacking on that again :)
> >
> 
> Maybe for OpenBMC Fix it next week? :D

Added it to the list

Andrew

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2018-06-07  2:44 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-05-30 21:04 OpenBMC Security Working Group Kick Off Nancy Yuen
2018-05-31  8:38 ` Stewart Smith
2018-05-31 19:53   ` Vernon Mauery
2018-06-01  0:38   ` Andrew Jeffery
2018-06-06 22:35     ` Nancy Yuen
2018-06-07  2:44       ` Andrew Jeffery

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).