Would it be possible to allow the person who placed the computer to modify the rom directory or allow its modification only when a new computer is placed (computer must be backed up and replaced to fix)?
This system could become 100% secure simply by requiring that the person labels their computer and the OS checks the computer's ID every startup to verify that a potential hacker hasn't (somehow) copied all files off and replaced the computer with a new one. On top of that, the hacker wouldn't even be able to obtain the files without breaking into the OS, assuming the OS is custom and supports user-level security (or file encryption).
Here's how exactly it could work...
- User places a new computer (new ID generated)
- Computer asks the user if they want to modify the rom (recommends to select "no")
- If yes, computer opens up into a basic shell where the user is asked to select a disk drive containing the new rom
- Computer then resumes running by going through the OS's security checks (OS handles sandboxing, etc).
- User now has a secure computer.
Edited by Ajt86, 12 January 2016 - 02:51 PM.












