|
|
|
|
|
by Arnavion
882 days ago
|
|
>The second relies on DBX not being updated, for which the remedy is "don't do that". Not updating DBX is the default state. Updating it is what requires effort. How many devices actually have up-to-date DBX? I know I mentioned LVFS in my first comment, but I have to wonder how many Linux devices with SB enabled actually use it. The ones that don't will not have updated their DBX since they were manufactured. >The idea is that your main data partition is encrypted with a key held in a secure enclave [...] You're missing the point. An attacker that can write to the ESP is root on the live system right now. It can exfiltrate the contents of `/` right now. Or if it can't exfiltrate right now, it can install an OS service to do that on future boots. |
|