Post #3187120
2024-07-28 15:49 UTC
@dangoodin@infosec.exchange nitpick: Secure Boot cannot and does not protect against firmware-level malware. That was never the goal. Secure Boot is intended to protect against booting a compromised operating system. That's all it can do, by design. And as this key leak shows, it's a pretty bad design at that.
The better approach would have been implementation of a plain measured boot environment, used for deriving a system image unlocking key. If the machine was manipulated, key derivation would fail.
Replies (0)
No replies.