"I thought firmware UIs are so diverse that it is unreasonable/impossible to guide users to the secure boot options."
While I'm impressed by Matthew's work, I never understood this (fundamental!) argument of his.
1. There are NOT that many BIOS vendors and there are NOT that many different BIOS interfaces. 2. People need to mess with their BIOS ANYWAY to boot from a CD or USB stick!
PS: I know and like and use GRUB4DOS but it's much less newbie friendly than all the above.
Power management, mobile and firmware developer on Linux. Security developer at Aurora. Ex-biologist. mjg59 on Twitter. Content here should not be interpreted as the opinion of my employer. Also on Mastodon.
Re: Approach eases social engineering attacks
Date: 2012-10-20 01:09 pm (UTC)While I'm impressed by Matthew's work, I never understood this (fundamental!) argument of his.
1. There are NOT that many BIOS vendors and there are NOT that many different BIOS interfaces.
2. People need to mess with their BIOS ANYWAY to boot from a CD or USB stick!
PS: I know and like and use GRUB4DOS but it's much less newbie friendly than all the above.