3 ms·
That's not strictly true. In my view, Boot Guard is sort of like a locked bootloader. In Boot Guard, the CPU verifies a signature on system firmware before load
by ENOTTY 7y ago
That's not strictly true. In my view, Boot Guard is sort of like a locked bootloader. In Boot Guard, the CPU verifies a signature on system firmware before loading it. The signature is verified using a public key from the platform manufacturer. So under the Boot Guard regime, the platform manufacturer essentially gets a vote in whether your platform can run modified firmware level code. Or you find a jailbreak.
- incompatible 7y agoOK, in that case I'd be very interested to know which motherboard manufacturers are friendly to installation of replacement firmware and which not. coreboot.org links to libreboot.org, but the list of supported hardware is pretty short: https://libreboot.org/docs/hardware/ https://libreboot.org/docs/hardware/
- ENOTTY 7y agoI think purism might be amenable. Worth double checking with them.
- incompatible 7y agoThey don't even use Intel CPUs, it seems. Boutique vendors would be out of my price range, and the few boards supported by Libreboot seem to be circa 2009 models, presumably preceding Boot Guard. I doubt that it's something I'll be using any time soon.