lsorense: (Default)
lsorense ([personal profile] lsorense) wrote in [personal profile] mjg59 2011-09-23 05:43 pm (UTC)

Locking down the boot drive is to try to prevent someone with physical access to the machine from booting from another drive.

This is about preventing malware from replacing the bootloader with malware that loads before the OS and antivirus software.

Of course the method by which it does it is not that it prevents malware from replacing the bootloader, but rather prevents the machine from booting when malware has replaced the bootloader. In other words malware that messes with the bootloader will make a secure boot enabled machine unbootable until it is cleaned with some other system. So it makes sure you know something messed with the bootloader by making your system unbootable.

Post a comment in response:

If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org