• unexposedhazard@discuss.tchncs.de
    link
    fedilink
    arrow-up
    7
    arrow-down
    6
    ·
    1 day ago

    Physical access = electronic waste

    Thats how it has always been and always will be. If a threat actor had free access to your device for even just a couple seconds, its compromised rare earth trash.

      • ulterno@programming.dev
        link
        fedilink
        English
        arrow-up
        6
        arrow-down
        1
        ·
        1 day ago

        Nope

        Exactly.
        Silicon is not a rare earth element.
        Neither is Aluminium nor plastic nor Lithium (it’s getting rarer alright, but doesn’t fall into the category).

        The amount of rare earth elements is really small in these devices.

      • unexposedhazard@discuss.tchncs.de
        link
        fedilink
        arrow-up
        4
        arrow-down
        1
        ·
        1 day ago

        Explain. The way i understand it, if somebody flashes malware into your firmware or bootloader then that device cant really be guaranteed to ever be safe again.

        • amino@lemmy.blahaj.zone
          link
          fedilink
          arrow-up
          2
          ·
          edit-2
          19 hours ago

          i know this is not for PCs but GrapheneOS uses the Google Titan chip and this app to solve that problem.

          might be a long time before we get similar hardware for PCs. the only thing that’s remotely similar is the Apple T2 for MacBooks but there’s no Linux distro with comparable security to GrapheneOS yet.

        • 9tr6gyp3@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          1 day ago

          Secure boot helps protect against evil maid attacks by checking hardware and OS signatures. If the boot process has been tampered with, the user can be alerted that the secure boot process can no longer properly verify signatures.

          While its probably true that you can no longer guarantee that system can be used safely ever again, at least you will be aware that it was tampered with and you can go ahead and send that system to e-waste and get you a new system.