• Lembot_0004@discuss.online
      link
      fedilink
      English
      arrow-up
      1
      ·
      17 hours ago

      Does BIOS have secure boot?

      No. And that is a good thing.

      Or can secure boot be built upon anything?

      Yes, the kernel loader can do whatever check you want.

        • Lembot_0004@discuss.online
          link
          fedilink
          English
          arrow-up
          1
          ·
          16 hours ago

          It is already late if your boot sector is writable by anyone who wants to. Moreover, the boot sector isn’t writable if you get access just to the FS.

          • the_crotch@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            4
            ·
            16 hours ago

            If I managed to get root, either by compromising account credentials or using some sort of escalation exploit, I could write whatever I wanted to the boot sector. Secure boot will prevent that modified boot sector from booting.

            “More security is a bad thing” is a weird take