Practical security for 2014
Practical security for 2014
Posted Jan 14, 2014 16:28 UTC (Tue) by mjg59 (subscriber, #23239)In reply to: Practical security for 2014 by paulj
Parent article: Practical security for 2014
"Just for the record, this claim for SecureBoot is patently incorrect. Any exploit of incorrectly handled persistent state (e.g. config or other policy files, hardware database files) will remain persistent, as discussed before."
Nonsense, because Secure Boot ensures that we have a mechanism to perform updates of the affected components without having to parse that persistent data with vulnerable software.