5 ms·
Please ... just give me back my BIOS.
by jerhewet 1y ago
Please ... just give me back my BIOS.
- gruez 1y agoBIOS isn't magically secure either. It has no secureboot so it just runs whatever.
- Lammy 1y agoI refuse to endorse any mindset where my Personal Computer unquestionably running my code could be considered a bad thing.
- gruez 1y agoYou're conflating UEFI with secureboot. Moreover all the secureboot implementations I've seen allow you to either disable it or enroll your own keys.
- Lammy 1y ago> all the secureboot implementations I've seen allow you to either disable it or enroll your own keys Here you go — now you have. Thank ${DEITY} for exploits! https://wiki.ubuntu.com/ARM/SurfaceRT#Secure_Boot https://wiki.ubuntu.com/ARM/SurfaceRT#Secure_Boot https://openrt.gitbook.io/open-surfacert/common/boot-sequence/uefi/secure-boot https://openrt.gitbook.io/open-surfacert/common/boot-sequenc...
- hulitu 1y agosecureboot also runs "whatever". It is just picky about which "whatever" it runs (hint: it runs the "whatever" for which Microsoft has the keys).
- lmm 1y agoIn theory, sure. In practice I'd bet UEFI-based systems are easier to compromise, because the attack surface is just so much larger.
- adrian_b 1y agoNevertheless, it is trivial to make any BIOS-based computer at least as secure as the most secure UEFI/secureboot-based computers. For that, any SSDs/HDDs included in the computer should be non-bootable and fully-encrypted. Then the BIOS will happily run whatever an intruder will attempt to run, but nonetheless the intruder will not have any access, neither for reading nor for writing, to the data hosted by the computer. The owner can boot from a removable USB memory, used as a computer key, whose content cannot be modified by someone else as long as the owner keeps it. All Intel/AMD CPUs have backdoors in the form of the System Management Mode and of various hardware management engines, which can be exploited by a malicious BIOS or UEFI firmware to monitor what the operating system that is controlled by the user does, but SecureBoot also offers no protection against such backdoors. ARM CPUs are no better, because many of them have copied Intel, so they have the equivalent of the SMM: EL3. If you run yourself a hostile application after booting, then SecureBoot also does not offer any protection against that.
- JCattheATM 1y ago> Nevertheless, it is trivial to make any BIOS-based computer at least as secure as the most secure UEFI/secureboot-based computers. Mmm....no. I use my own keys and removed vendors keys from my secureboot setup. Hard disk is encrypted and automatically pulls keys from the TPM to boot into a guest OS, which is running something akin to prey. If the hard drive is removed, it can't be read or examined, and you can't replace the HDD with a different OS to get it to boot. How would you recreate that setup with just a BIOS?
- adrian_b 1y agoThe setup that I have described has identical behavior, except that I use a removable USB memory (containing a bootable OS kernel and encrypted SSD/HDD keys) instead of a TPM and a firmware implementing SecureBoot, which are included in the computer motherboard. In my variant, you do not need to trust anyone but yourself, because an attacker will have access only to a system where the component that needs to be secure is not present. In your variant, you must trust the vendors of the TPM and of the firmware, that their products do not have either intentional backdoors or bugs that would allow the extraction of the secret keys. Having seen first hand how the development of "secure" products is done even at the companies that do not have bad intentions, I do not trust anyone, except myself.