this post was submitted on 17 Nov 2023
14 points (93.8% liked)
Framework Laptop Community
2649 readers
5 users here now
Related links:
- Framework website: https://frame.work/
- Official Framework Mastodon: https://fosstodon.org/@frameworkcomputer
Related communities:
- Buy it for life community: !buyitforlife@slrpnk.net
- Fairphone community: !fairphone@lemmy.ml
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
how does boot guard work? can you not just flash new firmware using a ch341a programmer?
Intel Boot Guard stores the public signing key in OTP fuses inside the PCH. Meaning that you need the private key to sign new BIOS firmware. This "feature" has existed since Haswell 4th gen processors.
This is a simplified description of how it works because it's still beyond my full understanding.
More info here: https://github.com/corna/me_cleaner/wiki/Intel-Boot-Guard