4 ms·
Well, I thought so. But then I looked at the 11th gen that I have. The BIOS is signed by a key, and the hash of the key is fused into the HW. Anything 11th ge
by treffer 4y ago
Well, I thought so. But then I looked at the 11th gen that I have.
The BIOS is signed by a key, and the hash of the key is fused into the HW.
Anything 11th gen or newer locks libreboot or coreboot out.
Search for FPF OTP FUSE. It is an interesting topic. I want to drop intel ASAP due to this.
- mlyle 4y ago> Anything 11th gen or newer locks libreboot or coreboot out. Not all OEMs are doing this. (And some are even shipping 11th generation with coreboot). But you're right in that it's making things worse.
- treffer 4y agoWell, intel ships a tool that tells the OEM that this is a misconfiguration from a secure boot configuration POV. Linux fwupdmgr can be used to verify the secure boot status and you will fail HS2 if this is not fused. Also.... would be happy to know who doesn't fuse it on newer machines. And even coreboot does not mean you can flash your own. You can have a lockdown where you can only load the OEMs coreboot.