now you have to do that not only for every motherboard, you have to do it for every BIOS revision released for that motherboard. And when new BIOS updates are released, you have to re-do the hack.
you are talking as if the secure boot is a nicely delineated chunk of the BIOS, when everything is just the optimized binary blob, the location of this chunk may vary from BIOS to BIOS.
the source code implementations may be few, but the resulting binary chunks will vary a lot more.
Posted Feb 3, 2013 0:55 UTC (Sun) by mjg59 (subscriber, #23239)
[Link]
"you are talking as if the secure boot is a nicely delineated chunk of the BIOS, when everything is just the optimized binary blob"
That hasn't been true for a long time. It's completely untrue when it comes to UEFI.
A pair of UEFI updates
Posted Feb 3, 2013 5:23 UTC (Sun) by theophrastus (guest, #80847)
[Link]
Thank you both. (i think we always learn more watching a spirited discussion than if everyone just tediously agrees)
i lost track of LinuxBIOS and am glad to see that work on it continues. of course, i was thinking more of an unlikely... -patch- to remove, or jumper around, UEFI, instead of the full nuclear option; but that might be the only way in the final analysis. as long as hardware makers are willing manufacture to suit a narrow, (yet fat), market.
A pair of UEFI updates
Posted Feb 3, 2013 11:22 UTC (Sun) by khim (subscriber, #9252)
[Link]
You can not "jump around" UEFI because it's the only thing there is.
BIOS is emulated on top of UEFI, not the other way around. Which means that all the hardware is initialized in the UEFI.