From 2507fe125561775c15ab1fccbb38d416ba006f07 Mon Sep 17 00:00:00 2001 From: Andrew David Wong Date: Sat, 19 Jan 2019 17:27:37 -0600 Subject: [PATCH] Acknowledge special USB drives --- installing/install-security.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/installing/install-security.md b/installing/install-security.md index e82d65b3..1eba07e3 100644 --- a/installing/install-security.md +++ b/installing/install-security.md @@ -75,6 +75,10 @@ Cons: untrusted ISO to dom0 in order to burn it to disc, which leaves only the other two options.) +Considering the pros and cons of each, perhaps a USB drive with non-rewritable +(or at least cryptographically-signed) firmware and a physical write-protect +switch might be the option. + [verify]: /security/verifying-signatures/ [classic problem]: https://www.ece.cmu.edu/~ganger/712.fall02/papers/p761-thompson.pdf