Poettering: Brave new trusted boot world
Poettering: Brave new trusted boot world
Posted Nov 2, 2022 16:51 UTC (Wed) by luto (subscriber, #39314)In reply to: Poettering: Brave new trusted boot world by farnz
Parent article: Poettering: Brave new trusted boot world
> Your attack scenario depends on convincing the system to load a malicious application - if the firmware and boot menus are bug-free and locked down to only load approved applications from the system, then this is not possible.
This essentially means using a custom Secure Boot configuration, right? And setting a firmware password so an attacker can’t simply turn off or reset Secure Boot.
UEFI could have done so much better in this regard. In theory DRTM / Secure Launch / TXT could do a better job here.
