Conversation

Verified boot is one of MANY missing hardware security features, not the only or even the primary one, as stated earlier. You're not accurately representing what is lost, including ongoing security support and in one of the cases, an OEM not actively hostile to security...
2
1
> Evil maid is the obvious risk I understand. Verified boot is again one of many core hardware-based security features. I don't think it's anywhere near the highest importance among them. You're missing a lot more than verified boot. I don't know where you get the idea that's
1
the major piece of the puzzle that's missing. In particular, the Librem 5 has gone out of the way to prevent full firmware upgrades, and has used hardware with very lackluster security and serious security issues. The OS is just a piece of the privacy/security stack as a whole.
2
claims about it and misrepresent the compromises involved as you are repeatedly doing. My recommendation to you was to at least use the Pinephone and avoid worse problems. If you want to ignore that recommendation, that's fine, but don't expect me to spend more time on this.
1
Also, verified boot is PRIMARILY not about defending against physical tampering. The primary threat model is persistent compromise. So even when it comes to that feature, which is dwarfed by the importance of other aspects of hardware security, you present it in a warped way.
2
1
Show replies