3 ms·
Why not?
by ThrowawayTestr 8mo ago
Why not?
- madduci 8mo agoBecause this can end very badly. It is a new surface to attack
- yjftsjthsd-h 8mo agoMaybe? What's your threat model?
- M95D 8mo agoExactly! It's actually great! More ways to jailbreak stuff.
- eqvinox 8mo agoWhy is it a new surface? Either you can run UEFI code, or you can't. Attacking the JS interpreter itself is unrealistic IMHO, it's the poorly written JavaScript running on top of this that might open new surfaces of attack. But other UEFI code is mostly written in C or C++, so let's call that a wash?