(no title)
PrimaryAlibi | 1 year ago
Is it just from userspace you flash these firmware (other than boot rom)? Or can you flash externally as well if you have physical access?
This also means that just like you avoid a lot of malware by going to linux instead of windows which is what all hackers build their malware for, you can probably also avoid a lot of these firmware bootkits by flashing coreboot instead of having UEFI.
bigfatkitten|1 year ago
You could flash coreboot and run your own secure boot chain etc on one machine, but this is absolutely not something you can do at organisational scale.
That said, only individuals worried about foreign intelligence services need to incorporate this into their threat model.
PrimaryAlibi|1 year ago