Hacker News new | ask | show | jobs
by osy 2232 days ago
Boot Guard is not implemented on most (all?) self built machines and a lot of pre-builts as well. But even if it is enabled, UEFI variables are not protected at all. You can disable Secure Boot just by overwriting UEFI variables and then boot any arbitrary code from USB.
1 comments

Which will change the measurements in PCR7, which is a detectable event that will break Bitlocker unsealing.