• @[email protected]
    link
    fedilink
    1
    edit-2
    2 months ago

    Signal data will be encrypted if your disk is also encrypted.

    True.

    and you don’t have any type of verified boot process

    How motherboard refusing to boot from another drive would protect anything?

    • @9tr6gyp3
      link
      12 months ago

      Its more about protecting your boot process from malware.

      • @[email protected]
        link
        fedilink
        1
        edit-2
        2 months ago

        Well, yes. By refusing to boot. It can’t prevent booting if motherboard is replaced.

        EDIT: s/do anything/prevent booting/

        • @9tr6gyp3
          link
          12 months ago

          Thats correct. Thats one of the many perks.

            • @9tr6gyp3
              link
              12 months ago

              If the hardware signatures don’t match, it wont boot without giving a warning. If the TPM/Secure Enclave is replaced/removed/modified, it will not boot without giving a warning.

              • @[email protected]
                link
                fedilink
                1
                edit-2
                2 months ago

                If the hardware signatures don’t match

                Compromised hardware will say it is same hardware

                If the TPM/Secure Enclave is replaced/removed/modified, it will not boot without giving a warning.

                Compromised hardware controls execution of software. Warning is done in software. Conpromised hardware won’t let it happen.

                • @9tr6gyp3
                  link
                  12 months ago

                  Compromised hardware doesn’t know the signatures. Math.

                  • @[email protected]
                    link
                    fedilink
                    12 months ago

                    Compromised hardware can’t create new signatures, but it doesn’t matter because it controls execution of software and can skip any checks.