• deadcadeA
    link
    fedilink
    arrow-up
    45
    ·
    7 months ago

    Since the EFI partition is unencrypted, physical access would do the trick here too, even with every firmware/software security measure.

    • _edge@discuss.tchncs.de
      link
      fedilink
      arrow-up
      23
      ·
      7 months ago

      True, but this was the case without this finding, wasn’t it? With write access to the EFI you could replace the boot loader and do whatever you please.

      • deadcadeA
        link
        fedilink
        arrow-up
        3
        ·
        7 months ago

        Unless a proper secure boot + FDE setup is in place.