3 ms·
What you are describing is Intel BootGuard. [1] There is a signature burned into efuses in the CPU that is used as a root of trust for the BIOS, which implemen
by kogepathic 9y ago
What you are describing is Intel BootGuard. [1]
There is a signature burned into efuses in the CPU that is used as a root of trust for the BIOS, which implements SecureBoot.
In theory this protects the boot chain from tampering. In practice vendor BIOS implementations are usually buggy garbage, so while you cannot replace the BIOS (because then the signature would fail and the platform won't boot) it may be possible to circumvent the security features by exploiting some bug in the IBV code or in their UEFI implementation.
[1] https://patrick.georgi.family/2015/02/17/intel-boot-guard/ https://patrick.georgi.family/2015/02/17/intel-boot-guard/