Practical security for 2014
Practical security for 2014
Posted Jan 10, 2014 8:16 UTC (Fri) by ibukanov (subscriber, #3942)Parent article: Practical security for 2014
At least Samsung ARM Chromebook allows to replace the firmware and get a custom verified boot, but doing that is non-trivial, http://krblogs.com/post/63809988096/bootloader-unlock-on-...
Of cause, it would be nice if Google would allow to add an extra signing key to the stock firmware similar to what Microsoft requires, but that is a double-sword. There are attacks when users are tricked to install an extra root certificate in the browser as a a part of "enabling advanced gaming features". I would not be surprised that with a user-friendly key adding the same attack can be used to add a custom enabling persistent malware kernel.