Hacker News new | ask | show | jobs
by dosshell 1527 days ago
I don't recall why, it was so long time ago. But my best guess is that they wanted to guarantee that they know what has been booted?
1 comments

The sibling comment already mentioned evil maid attacks (not as much of an issue nowadays thanks to SecureBoot and TPMs), but there's also DMA attacks through physical ports: https://en.wikipedia.org/wiki/DMA_attack