I now have TOTP codes in my boot process, this is a protection against evil maid attacks!!!
The secret used to generate those codes is bound on values that depend on the system's state. Such that, if you changed anything that could compromise the system's trustworthiness, like modify the BIOS firmware or modify secure boot, then the codes cannot be generated.
A BIOS password can't stop someone from disabling secure boot if they reset the motherboard, but with this system, any tampering can be detected.
Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
(NekoSock) Miya Ironami (iro_miya@mk.absturztau.be)'s status on Saturday, 13-Jul-2024 23:34:49 JST(NekoSock) Miya Ironami