3 ms·
That depends - it's possible to have a first stage bootloader in mask or OTP ROM that hashes the firmware before passing off control. No idea if Macs do this th
by bdonlan 9y ago
That depends - it's possible to have a first stage bootloader in mask or OTP ROM that hashes the firmware before passing off control. No idea if Macs do this though.
- magnat 9y agoWhy bother with providing userland tool then? If you have complete chain of trust, the tool can just MsgBox("Everything's OK") because you wouldn't be able to boot OS if EFI didn't pass the check. If you don't have a chain of trust, the tool can be easily tampered with by the rootkit. Either way - it serves no real security purpose other than perhaps reassuring user or detecting obsolete, existing rootkits.
- rothbardrand 9y agoI do believe the whole point of the TPM on macs is the make sure the firmware and ultimately OS is signed with Apple keys.
- amluto 9y agoA lot of newer Intel CPUs can be programmed, via fuses, to refuse to boot unless the first-stage firmware hashes to a specified value.