Poettering: Brave new trusted boot world
Poettering: Brave new trusted boot world
Posted Nov 6, 2022 3:10 UTC (Sun) by nybble41 (subscriber, #55106)In reply to: Poettering: Brave new trusted boot world by farnz
Parent article: Poettering: Brave new trusted boot world
> On all the Secure Boot devices I've owned, if there is a firmware password set, then the only way to change the boot option is to enter the firmware password - otherwise, the device will only boot the single entry it's been configured to boot (the Linux OS on the SSD in the case of my current laptop).
But does it identify "the single entry it's been configured to boot" in a secure way, such as a hash of the boot image or its signing key? If not, one could still swap out the boot device for another one with the "same" entry (same identification), but controlled by the attacker. If that ultimately results in a system with PCR 11 not initialized (zero) then the attacker could feed in the expected measurements after booting their own OS and obtain the keys to unlock the encrypted storage.
