I understand LUKs can be used to encrypt your data. But what would prevent somebody plug in a USB with and just wipe my drive?
On traditional BIOS like Lenovo, HP, Dell and even Framework you can set a supervisor password that locks the boot menu. So nobody can boot from the USB.
Coreboot is different though. I spoke with Starlabs whose computers run Coreboot, and apparently you can have the boot menu password. OTOH, Sys76’s Coreboot doesnt allow such things.
I ask because i want to libreboot my T480, but the number 1 thing i worry is unauthorized USB boot.
This one: https://libreboot.org/docs/linux/grub_hardening.html#grub-password
seems to only lock the ability to edit the grub entry freely, aka press “e” to change stuff when grub fails to boot.
But what would prevent somebody plug in a USB with and just wipe my drive?
If they have enough access to plug in a USB key, they have enough to smash the drive (or the entire machine) with a sledgehammer. Or move it to another machine that they control and wipe and reimage it there.
(Shades of the xkcd with the crypto-nerd and the pipewrench: there’s always a non-technical, or less-technical, solution when it comes to security.)
Imo any attacker that has access to the hardware cannot be countered by software. There always is a badusb or sodder this here chip type attack possible against any attempt at locking up your pc.
You can encrypt and backup, but any legends about tpm, bios passwords, weird hardware encryption features and keys are moot once an attacker can read what transits on the pcie or memory bus
I’ve always remembered the saying “physical access is total access.”
Disable the boot menu and set a password on your UEFI before considering Libreboot.
Nothing will prevent him from wiping your drive if he has physical access to your device.
Sure you can use stuff like Secure Boot with your own custom keys to lock it. Then noone can indeed just boot it.
Doesn’t stop that person from removing your drive and plugging it into another pc. Or from just smashing your disk to pieces.
The same goes for stuff like a bios password. With physical access you can wipe that, too. It’s just a bit more work (or requires additional tools) than just an USB stick.
In short: Yes, you can stop someone from just booting an USB stick and wipe you drive. But it doesn’t matter if he has other ways to do the same. Protection only works as a whole concept, Software won’t help you when physical security allows the device to be stolen. And seriously? Who cares if their stolen laptop is wiped, smashed or drowning on the bottom of the ocean. It’s gone anyway.
The actual protection for data is a) backups so you don’t lose them and b) encryption so nobody can read them.
why assume the attacker is a guy?
Because the fictious person stealing your laptop and drilling through your disk to erase it identifies as male. I have a whole backstory worked out if you are interested…
Or because it doesn’t matter at all and two letters were simply the shortest.
There can be multiple reasons:
- Commenter just had a slip up and thought of it as a masculine profession which is fine. It does happen.
- Commenter’s first language is not English. Czech for example doesn’t use they/them for a single person unless it is neo-pronouns. So instead we just gender based on word of a profession, which is 99% of the time masculine. Only exception that comes to mind is a nurse which translates to homonym of sister. There are also feminine suffixes for jobs but that is only used if you know that the person who works it uses feminine pronouns or if the field is heavily dominated by women but then it is a prejudice.
how would you suggest to point this out to someone given what you said? (are you ok with people referring to all teachers as she or her since most teachers are women? seems like that would be annoying for men who teach)
In my example I’ve said that would be a prejudice. It is still more common to talk about a teacher as a man unless their pronouns are known, but they don’t give a fuck when it happens. I got called by both feminine and masculine pronouns in legal paperwork; it’s not a big deal and that comes from someone with a social gender dysphoria.
Name, next referred to only as person. And then feminine suffixes in upcoming legal fluff, because person is always feminine. Or a prosecutor and the rest is instead masculine. It is truly at bottom of a barrel of social problems and would require an eradication of multiple languages as they/them becomes used around B2 level of english and even then it slips, because mother tongue is a mother tongue.
Yes, I am in fact okay with refering to every teacher as he, because that’s what grammar in my native language demands (“Lehrer, der - masc.”). I will also happily refer to every guard as she, because –again– grammar ("Wache, die - fem.).
Genus != sexus != gender… One is grammar, one is biology, one is identity. Overlaps are purely coincidental. I don’t understand why especially English speakers can’t get the concept. I mean sure, they dumbed down their grammar so much that they lost the destinction, but even unrelated to language they seem to develop an insane fetish for conflating sexus and gender somehow. For example if you need to add “biological” before “gender” for your expression to make sense, that should be a hint that you are actually talking bout different things.
Fun fact: When English tried to move away from gender specific words and towards generic ones (all being actors, instead of speaking about actors and actresses), other languages did the exact opposite. Because when you language’s grammar has all nouns (arbitrarily) gendered, actresses and actors is a step forward from the generic actor (which often is male my grammatical definition). At least that was the theory in both cases. Two languages, two exactly opposite reactions to same fact. Why doesn’t it make any sense? Because it’s a fucking narrative to keep some culture war bullshit going. Language isn’t sexist. The Sexism filtering your words because they reach your brain is.
Why assume masculine pronouns inherently refer to a guy? /s
Funnily a lot of people consider “guy” as gender neutral nowadays…
what do you mean?
Yep. Physical access is equivalent to ownership. The only reasonable thing you can do to protect against it is to prevent access. Given enough time and physical access, any system can be compromised. Encryption is the only good prevention from them reading the data, but it isn’t foolproof, and backups are the only good way to ensure you can access the data after.
I’m not sure I follow why this would be a big concern. If your drive is encrypted the worst they can do is wipe your data, which would require restoring a backup image. A hassle but it won’t give them access to your data.
Technically you would also want to encrypt your RAM. But that’s depending on your threat model.
You could make it about equivalent to the protections afforded by the typical BIOS password, i.e. the attacker must first disassemble your laptop to reflash the spi chip or pull the hard drive. A
grub.cfglike so would do, assuming everything in encrypted partitions:set prefix=(memdisk)/boot/grub set superusers="myuser" password_pbkdf2 myuser grub.pbkdf2.sha512.10000.<your hashed password> cryptomount -u <UUID of LUKS container> search.fs_uuid <UUID of the root filesystem under LUKS container> root cryptouuid/<UUID of LUKS container> configfile ($root)/@rootfs/boot/grub/grub.cfgAssuming you boot directly to GRUB or locked out the SeaBIOS boot device selector, then GRUB will only ever look for a boot device matching your disk’s UUID; attempting to do anything else aside from entering the LUKS passphrase will prompt for the GRUB password. You’d still have your own recovery path by pressing Esc, entering your GRUB password, and dropping to the GRUB shell. Bonus points for patching the GRUB code so it doesn’t echo the UUID of your disk.
No, it isn’t bulletproof against physical access. But yes, I had the same question you did when starting out with coreboot and this was the solution I came up with.
Not sure if I’m helping. But sounds this could also be a X/Y problem… The way to make sure you don’t lose data is backups, not something else. I mean your SSD could as well die. Or someone doesn’t boot something, but steals the entire device… Or plugs in an USB Zapper. Backups deal with that. And deal with disk wiping as well.
Setting a BIOS password doesn’t really do much good. Someone can just unplug the CMOS battery and the password will be cleared. Even if it was stored in flash, it could be removed by erasing it with a flash programmer and flashing a new BIOS.
There are methods to detect if a device has been tampered with and disassembled. Like glitter nail polish on the screws.
Idk if libreboot is coreboot+ a specific payload.
But in edk2 which is used in dasharo you can set some UEFI boot targets and disable usb boot yes, of course also set a firmware password.
There is also HEADS which is another payload of coreboot and can use a hardware security key to need to approve boot drives. Makes most sense with very stable distros like Qubes though as you dont constantly re-sign everything
I have a t480 here. It took me about five minutes to unscrew the bottom panel, remove the ssd and replace the bottom panel like before.
Just make regular backups and practice restoring from them.
If someone has physical access to your laptop, can’t just turn it on and spill a glass of water on it?
Just here for the comments, since I know of no way to disallow booting from removable media. Although I did recently come across a modern Lenovo laptop whose BIOS simply lacked the menu entry to switch boot order, boot device and anything like that…
Edit: which isn’t a problem if you do full system encryption. You can even encrypt your boot partition. And even if an adversary dumped your system
fromto a removable media, decrypting that wouldn’t be a viable option unless they were a nation state level actor.since I know of no way to disallow booting from removable media.
newer bios’es give you the option of locking usb boot from behind a supervisor password.
– meaning that you have to give the supervisor bios password if you want to boot from usb.
Cool! 🛠️
Never used libre boot but I don’t see why it should not have a bios password like all bioses…?
Anyway if a bad actor has physical access to your laptop… Well…
Reading the comments makes me wonder why BIOS passwords were even invented.
Sounds like everyone is saying its a waste of time and to never use it if the biis supports it.
BIOS boot passwords were from another era with different needs and assumptions. In controlled access environments they can still have an impact if you have a proper chassis that has locks on it preventing removal of drives. Most normal people don’t possess such business class chassis. The scenario was a business environment with security teams, other employees, supervisors and locks that while you could cut them with heavy equipment you’d be noticed doing so. In terms of preventing a team of thieves breaking in with power tools and stealing things true it never was meant to prevent that. It’s more authorization and access control within an organization. The idea being perhaps the CEO’s machine or a special machine for accessing sensitive devices would be physically locked and have such a password installed as another layer of security that couldn’t be bypassed surreptitiously.
Additionally back in the day these BIOS boot passwords were paired with chassis intrusion alarms which went off every subsequent boot if the chassis was opened thanks to a sensor and the only way to clear that alarm was logging into the BIOS with an admin password.
Your gaming computer BIOS supports neither of these nor does your gaming motherboard have a chassis intrusion connector nor does your gaming case come with support for such a device.
But it was never about preventing data destruction even in these cases. It was more preventing access and making any such access more time consuming and likely to trip alarms to allow a response including evaluation of compromise by professionals.
If you want to protect your data make backups. If you want it well protected against determined parties who want to destroy all copies and/or thieves then locate a copy off-premises. If you can’t do that at least locate a copy within a bolted down safe.









