> On Thu, Jun 21, 2007 at 10:26:04AM -0700,
david@lang.hm wrote:
>> the bios doesn't have enough capability to talk to the outside world for
>> updates.
>
> Of course, although perhaps it could. More likely my thought was that
> the service when it decides to download an update, would include the
> updated bios image and put it on the boot drive where the existing bios
> can find it. No signature needs to be added to the boot drive or
> kernel, just checksums in the bios image.
>
>> what tivo actually does is very similar to this
>>
>> they encode into the bios the ability to check a checksum/signature for
>> the kernel+boot filesystem and if they don't match look to see if there is
>> another kernel+boot filesystem available
>>
>> then software on the boot filesystem checks to see if the rest of the
>> system has been tampered with before it mounts /