I wonder if any of the people crying "omg secure boot is dead, if I get owned I could have malware forever in my BIOS" are actually running a proper secure boot system with all the obvious backdoorable parts secured (at least those you can do anything about).
Not really. The closest you can come is securing your SPI BIOS flash with a secure interposer (a la Google) and eliminating as much flash as possible from the rest of the system (make sure everything is loaded at boot instead). The latter part is quite difficult to achieve 100%.
-
-
This is far more advanced than anything I've set up, and I am running a more secure chain than most people (SecureBoot and self-signed bootloader and encrypted disk). The effort required to go from that "kinda safe" state to "really really safe" is immense.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.