5 ms·
Thanks. My take is on this is root access -> stealthy bootkit. Further demonstrates "secure" boot and similar DRM is theater only.
by forward1 3y ago
Thanks. My take is on this is root access -> stealthy bootkit. Further demonstrates "secure" boot and similar DRM is theater only.
- AshamedCaptain 3y agoOn the defense of the secure boot illusionists, though, I'm going to imagine that _anyone_ who was actually concerned about secure boot working as intended would have disabled the running kernel from accessing UEFI variables and the UEFI system partition.
- k8svet 3y agoAFAIK, while supporting XBOOTLDR, the systemd project still encourages /boot to be on the ESP if possible. Personally, I don't understand why they advocate this. Beyond separation of concerns and situations like this, it also seems more realistic to advocate for XBOOTLDR style deployments in the face of dual boot systems and Windows creating an anemic ESP nowadays.
- gunapologist99 3y ago> Personally, I don't understand why they advocate this. It seems easier to explain if you don't mind choosing from a nice range of conspiracy theories about what systemd is and why it has spread like a virus.
- amluto 3y ago> disabled the running kernel from accessing UEFI variables and the UEFI system partition. How exactly do you propose doing that? I suppose you could see if OPAL can block writes to the ESP, but that does nothing about efi vars.
- AshamedCaptain 3y agoKernel lockdown