"Another example would be the hack of SoftLayer. Hackers modified the firmware on the BMC from a bare metal host the cloud provider was offering. This shows another mistake in having blinders on and not being conscious of the other layers of the stack and the entire system."
Does anyone know whether dedicated hosting companies such as Hetzner or xneelo reflash the firmware on server boards (and disks and everything with firmware in it) before they rent it out again?
And whether they use more forceful hardware techniques to do the reflashing, and not software to politely ask the firmware to reflash itself?
I would hope they would but I can't find any security policy showing they do, or how.