I understand LUKs can be used to encrypt your data. But what would prevent somebody plug in a USB with and just wipe my drive?

On traditional BIOS like Lenovo, HP, Dell and even Framework you can set a supervisor password that locks the boot menu. So nobody can boot from the USB.

Coreboot is different though. I spoke with Starlabs whose computers run Coreboot, and apparently you can have the boot menu password. OTOH, Sys76’s Coreboot doesnt allow such things.

I ask because i want to libreboot my T480, but the number 1 thing i worry is unauthorized USB boot.

This one: https://libreboot.org/docs/linux/grub_hardening.html#grub-password

seems to only lock the ability to edit the grub entry freely, aka press “e” to change stuff when grub fails to boot.

  • hendrik@palaver.p3x.de
    link
    fedilink
    English
    arrow-up
    11
    ·
    edit-2
    3 days ago

    Not sure if I’m helping. But sounds this could also be a X/Y problem… The way to make sure you don’t lose data is backups, not something else. I mean your SSD could as well die. Or someone doesn’t boot something, but steals the entire device… Or plugs in an USB Zapper. Backups deal with that. And deal with disk wiping as well.