3 ms·
> If someone gains physical access to one of my devices, they can do any number of things to compromise it. They really cannot. Of course, this means you have
by fuzzy2 4y ago
> If someone gains physical access to one of my devices, they can do any number of things to compromise it.
They really cannot. Of course, this means you have to properly secure other knobs as well: Setup password, custom certificates (so a compromised Redmond certificate is irrelevant, configure your OS to use measured boot and abort on all changes, ...
This would mean: Secure Boot cannot be disabled; Software cannot be swapped out; DMA devices cannot be added.
If properly implemented, Secure Boot, a TPM and full-disk encryption will create a PC that cannot be internally compromised by regular thread actors. External additions (keyloggers and the like) are still possible of course.
- michaelt 4y agoThe idea there are NSA spies who are simultaneously so active they'll sneak into my home and open up my PC to install a bootloader backdoor, and yet so passive they won't plug in a $5 hardware implant seems.... unlikely.