Anyone know of good resources for securing USB and disk firmware? I've found the CCC presentations rather enlightening, as well as Andrew Huang's amazing work, but still feel like we live in the dark ages with respect to hardware security.
presumably an OS-level mitigation could intercept (some) attempts to write to drive firmwares, but I'm not aware of any actual implementations. it's a very ugly situation.