|
|
|
|
|
by hollerith
695 days ago
|
|
>As I understand it, that's both the whole point of, and limitation to, the hardware root of trust - it can't be changed even with a firmware update. The OP states that the vendors could have revoked the compromised platform key with a firmware update. They just didn't bother. |
|
That does make it quite difficult to pull off any kind of key rotation. I'm not sure, but I think (well known Secure Boot tool) sbctl is saying that you can sign a bootloader with multiple keys, which would permit creating a bootloader that would work with the compromised & the new root-of-trust, which at least opens some window of possibility. https://github.com/Foxboron/sbctl/blob/master/docs/sbctl.8.t...