3 ms·
Properly designed hardware with signed firmware versioning has the bootloader permanently disable the ability to blow efuses until reboot before passing control
by devit 3y ago
Properly designed hardware with signed firmware versioning has the bootloader permanently disable the ability to blow efuses until reboot before passing control to the OS, either through hardware or a mandatory hypervisor (and the bootloader itself is trusted and cannot be replaced without either a signature or special physical hardware access).