1 2 3 4 h'p://icons.iconarchive.com/icons/hopstarter/malware/icons-­‐390.jpg h'p://www.iconarchive.com/show/windows-­‐8-­‐icons-­‐by-­‐icons8/Security-­‐Security-­‐
Checked-­‐icon.html 5 The point is, people understand how to recover from other problems. They wipe/
replace the hard drive and reinstall soJware. They don't know how to recover from firmware a'acks. 6 This is the best possible case, where the BIOS is exposed for easy reflash. 7 8 9 10 11 "We got interested in 2009, but it took us a couple years to shiJ from our focus on Windows kernel security to finding meaningful new firmware problems & soluWons." This year or next will be the high watermark, surpassing 2009's spike of interest. 12 13 h'p://www.wickes.co.uk/content/ebiz/wickes/invt/213633/Facing-­‐Brick_large.jpg 14 h'p://www.veryicon.com/icons/system/agua-­‐stacks/evil-­‐stack.html h'ps://cdn1.iconfinder.com/data/icons/GiJs/512/box1.png 15 "It's one thing for someone to say what's clearly architecturally possible, and it's another to show a video of specific soJware being compromised or security soJware being bypassed." h'p://2.bp.blogspot.com/-­‐BtStmGpZOts/TsCIMLUXvwI/AAAAAAAACAc/
N19iHf_pGms/s1600/hands_twiddling_thumbs_fast_lg_nwm.gif 16 h'p://peteandgerrys.com/tag/pete-­‐gerrys-­‐heirloom-­‐eggs/ h'p://peteandgerrys.com/wp-­‐content/uploads/2012/04/Combo-­‐in-­‐Basket.jpg 17 h'ps://hbslp.files.wordpress.com/2013/04/dwight-­‐schrute-­‐false.jpg 18 19 20 21 22 23 24 25 26 27 28 29 30 Compare two of the same machines over 2me, and show correla2on to the UEFI flash filesystem. Show one example which is "natural" changes between runs/reboots 31 32 33 34 35 36 37 38 39 40 41 42 43 44