|
|
|
|
|
by dlcarrier
43 days ago
|
|
I miss having write disable jumpers on early Flash BIOSes. Considering that writing firmware requires local root access in the first place, and that there's no guarantee that there isn't a fault in Secure Boot, it doesn't do anything to prevent your system from being compromised, and only reduces but does not eliminate the possibility of a compromise being persistent, whereas a hardware jumper would do more to increase security, without the need for a central authority. |
|
Completely agree. My sarcasm did not quite show through in my post. I've always found UEFI security to be more to do with financial security for Microsoft whereas malware can bypass all of that, same with the evil maid agency stooges and that's even before getting into JTAG debugging on most devices. I see UEFI certificates as security theater.