5 ms·
Boot Guard is not implemented on most (all?) self built machines and a lot of pre-builts as well. But even if it is enabled, UEFI variables are not protected at
by osy 6y ago
Boot Guard is not implemented on most (all?) self built machines and a lot of pre-builts as well. But even if it is enabled, UEFI variables are not protected at all. You can disable Secure Boot just by overwriting UEFI variables and then boot any arbitrary code from USB.
- mjg59 6y agoWhich will change the measurements in PCR7, which is a detectable event that will break Bitlocker unsealing.