I would suggest having a user-replaceable key and on boot, displaying the public key (to avoid surreptitious replacement) and confirmation that the BIOS signature is correct.
Power management, mobile and firmware developer on Linux. Security developer at Aurora. Ex-biologist. mjg59 on Twitter. Content here should not be interpreted as the opinion of my employer. Also on Mastodon.
Re: Suggested fix?
Date: 2015-02-16 11:21 pm (UTC)