
11/17/2020 · Derek Chamorro, Ryan Chow
What this post added
This post introduces Cloudflare's implementation of hardware secure boot using AMD's Platform Security Boot (PSB) on their servers. It details the boot process, the limitations of UEFI secure boot against firmware attacks, and how PSB, anchored in immutable hardware (AMD PSP), provides a more robust root of trust by authenticating the initial BIOS/UEFI code before execution. It also outlines the Public Key Infrastructure (PKI) and build process involved in establishing this hardware-rooted integrity.