|
|
|
|
|
by kogir
59 days ago
|
|
With secure boot, full disk encryption, and robust backups, this risk should be largely mitigated, right? That’s what I’m personally banking on. I think anyone with the resources to bypass these would first just use a rubber hose. |
|
As for Secure Boot, maybe? I haven't thought through how that would help in this context, but my instinct is to ask how you'd do the binding between “I intend to boot Y instead of X” and “only accept the boot signature for Y instead of X”, so that malware can't try to unexpectedly substitute X. It feels like there's probably places for attackers to mess around here unless you're very careful.