3 ms·
Locking the bootloader (to enable verified boot) isn't only a protection against physical attacks. It also ensures that any deep OS exploit that occurs is not p
by lberrymage 4y ago
Locking the bootloader (to enable verified boot) isn't only a protection against physical attacks. It also ensures that any deep OS exploit that occurs is not persistent since the base OS is cryptographically verified on boot. This is really important to the security model, because otherwise you have no reliable way to protect against persistent exploits or verify that you're running a genuine release of the OS you think you are.