verified boot #298

Closed
subproc opened this Issue Jun 3, 2016 · 1 comment

Comments

Projects
None yet
2 participants
@subproc

subproc commented Jun 3, 2016

it's more a question that an issues....but why we need verified boot if it's telling us we have load a different os than the default whitout the possibility of knowing if we are using a tempered one?

@thestinger

This comment has been minimized.

Show comment Hide comment
@thestinger

thestinger Jun 3, 2016

Contributor

It can't be tampered with, because it prevents the key from being changed... that's the point of verified boot. The bootloader is informing you that a non-OEM key is being used, and it shows the fingerprint at the bottom. The fingerprint doesn't need to be verified for it to provide security, since the key can't be changed without unlocking the phone.

Regardless, this isn't part of CopperheadOS. It's a feature of the bootloader, which is not something that we can change or replace.

Contributor

thestinger commented Jun 3, 2016

It can't be tampered with, because it prevents the key from being changed... that's the point of verified boot. The bootloader is informing you that a non-OEM key is being used, and it shows the fingerprint at the bottom. The fingerprint doesn't need to be verified for it to provide security, since the key can't be changed without unlocking the phone.

Regardless, this isn't part of CopperheadOS. It's a feature of the bootloader, which is not something that we can change or replace.

@thestinger thestinger closed this Jun 3, 2016

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment