Y
Hacker News
new
|
ask
|
show
|
jobs
by
mjg59
1100 days ago
If you have secure boot enabled, how does the attacker replace the kernel or bootloader?
1 comments
lostmsu
1100 days ago
Pull the drive out, insert it into his machine, replace, then insert it back.
link
mjg59
1100 days ago
And now the signature doesn't match, so the system doesn't boot
link
lostmsu
1100 days ago
Which signature?
link
mjg59
1100 days ago
The signature that's validated by secure boot. If you don't have secure boot turned on then there's no point in verifying PCR 7, because all PCR 7 contains is the secure boot data.
link