Elektrine lite

← Feed

@datenwolf@chaos.social

Post #3187120

2024-07-28 15:49 UTC

@dangoodin@infosec.exchange nitpick: Secure Boot cannot and does not protect against firmware-level malware. That was never the goal. Secure Boot is intended to protect against booting a compromised operating system. That's all it can do, by design. And as this key leak shows, it's a pretty bad design at that. The better approach would have been implementation of a plain measured boot environment, used for deriving a system image unlocking key. If the machine was manipulated, key derivation would fail.

Replies (0)

No replies.