You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The proof of concept boots using uboot scripting and environment variables. Currently these variables are writable meaning that someone could easily bypass verified boot by running a few simple commands.
We need to either lock down the uEnv to RO (some things might break if we do this) or modify the verified boot mechanism so that security is not effected by env variables.
The text was updated successfully, but these errors were encountered:
Agreed, this board is for POC only anyway so just make it easy to enable/disable. There is a bootstrap pin for enabling/disabling verified boot so use this to force (as much as it can) verified boot when pulled.
Verified boot should still work when not forced on HW if configured in SW.
The proof of concept boots using uboot scripting and environment variables. Currently these variables are writable meaning that someone could easily bypass verified boot by running a few simple commands.
We need to either lock down the uEnv to RO (some things might break if we do this) or modify the verified boot mechanism so that security is not effected by env variables.
The text was updated successfully, but these errors were encountered: