I understand LUKs can be used to encrypt your data. But what would prevent somebody plug in a USB with and just wipe my drive?

On traditional BIOS like Lenovo, HP, Dell and even Framework you can set a supervisor password that locks the boot menu. So nobody can boot from the USB.

Coreboot is different though. I spoke with Starlabs whose computers run Coreboot, and apparently you can have the boot menu password. OTOH, Sys76’s Coreboot doesnt allow such things.

I ask because i want to libreboot my T480, but the number 1 thing i worry is unauthorized USB boot.

This one: https://libreboot.org/docs/linux/grub_hardening.html#grub-password

seems to only lock the ability to edit the grub entry freely, aka press “e” to change stuff when grub fails to boot.

  • nyan@sh.itjust.works
    link
    fedilink
    arrow-up
    7
    ·
    2 days ago

    But what would prevent somebody plug in a USB with and just wipe my drive?

    If they have enough access to plug in a USB key, they have enough to smash the drive (or the entire machine) with a sledgehammer. Or move it to another machine that they control and wipe and reimage it there.

    (Shades of the xkcd with the crypto-nerd and the pipewrench: there’s always a non-technical, or less-technical, solution when it comes to security.)