Skip to content
  1. Jun 01, 2022
  2. May 31, 2022
    • Sandrine Bailleux's avatar
      docs(threat-model): broaden the scope of threat #05 · 0677796c
      Sandrine Bailleux authored
      
      
       - Cite crash reports as an example of sensitive
         information. Previously, it might have sounded like this was the
         focus of the threat.
      
       - Warn about logging high-precision timing information, as well as
         conditionally logging (potentially nonsensitive) information
         depending on sensitive information.
      
      Change-Id: I33232dcb1e4b5c81efd4cd621b24ab5ac7b58685
      Signed-off-by: Sandrine Bailleux's avatarSandrine Bailleux <sandrine.bailleux@arm.com>
      0677796c
    • Sandrine Bailleux's avatar
      docs(threat-model): emphasize whether mitigations are implemented · 7e32cdb2
      Sandrine Bailleux authored
      
      
      For each threat, we now separate:
       - how to mitigate against it;
       - whether TF-A currently implements these mitigations.
      
      A new "Mitigations implemented?" box is added to each threat to
      provide the implementation status. For threats that are partially
      mitigated from platform code, the original text is improved to make
      these expectations clearer. The hope is that platform integrators will
      have an easier time identifying what they need to carefully implement
      in order to follow the security recommendations from the threat model.
      
      Change-Id: I8473d75946daf6c91a0e15e61758c183603e195b
      Signed-off-by: Sandrine Bailleux's avatarSandrine Bailleux <sandrine.bailleux@arm.com>
      7e32cdb2
  3. May 30, 2022
  4. May 26, 2022
  5. May 25, 2022
  6. May 24, 2022
  7. May 20, 2022
  8. May 19, 2022
  9. May 18, 2022
Loading