Hacker News new | ask | show | jobs
by Dibby053 20 days ago
Have the CPU and the security chip derive their private keys from physical unclonable functions (to prevent extraction), let them exchange public keys once during manufacture, and from that point onward encrypt the SPI bus.

This is what some smartphones seem to do. I don't know if server motherboards do it but it would help a lot against this kind of attack.