3 ms·
No, this line of thinking is basic threat modelling and stops us wasting time and effort on navel gazing when it would be better spent on things we can control.
by offices 3y ago
No, this line of thinking is basic threat modelling and stops us wasting time and effort on navel gazing when it would be better spent on things we can control. An invasive, non-destructive physical attacker also has access to (likely unencrypted) drives, memory buses, HIDs, audiovisual inputs...
'Fixing' this doesn't make your machine any less pwned if you let them touch it.
- blowski 3y agoThe linked article says it's not a problem with all implementations. This would suggest device manufacturers can defend against it, but some have chosen not to. Given the choice of a laptop where this risk is mitigated and one where it isn't, all other things being equal, I'd choose the one with protections in place.