Practical security for 2014
Practical security for 2014
Posted Jan 14, 2014 16:20 UTC (Tue) by paulj (subscriber, #341)In reply to: Practical security for 2014 by mjg59
Parent article: Practical security for 2014
The current state of affairs is that a single successful attack against your system can be turned into a persistent compromise - even if you fix the original bug, your system is still under the control of the attacker. Secure Boot provides mechanisms to ensure that that's not true.
Just for the record, this claim for SecureBoot is patently incorrect. Any exploit of incorrectly handled persistent state (e.g. config or other policy files, hardware database files) will remain persistent, as discussed before.
The notion that these attacks can not affect early boot, and that we are capable of building a very small and near perfectly reliable "trusted" subset of the OS is highly, highly optimistic.