3 ms·
Evil maid can flip your write switch. Longer version: Boot firmware and possibly OS boot loader must be unencrypted, thus attackable by an "evil maid" if left
by markjenkinswpg 8y ago
Evil maid can flip your write switch.
Longer version: Boot firmware and possibly OS boot loader must be unencrypted, thus attackable by an "evil maid" if left on device. Evil maid can flip the write switch. All other storage can be encrypted and is safer to leave on device.
Alternative approach, validate state of firmware on each boot with a TPM and a 2nd trusted device that you do keep with you such as a cell phone running Google authenticator or a hardware security module (HSM). See Trammell Hudson’s Heads https://trmm.net/Heads https://trmm.net/Heads and what's going on with Purism and Librem key https://puri.sm/posts/the-librem-key-makes-tamper-detection-easy/ https://puri.sm/posts/the-librem-key-makes-tamper-detection-...