Elektrine lite

← Feed

@mazzilius_marsti@lemmy.world

2026-09-08 16:27 UTC

Does Libreboot prevent unauthorized USB boot, aka somebody boot another OS and wipe your drive? I understand LUKs can be used to encrypt your data. But what would prevent somebody plug in a USB with and just wipe my drive? On traditional BIOS like Lenovo, HP, Dell and even Framework you can set a supervisor password that locks the boot menu. So nobody can boot from the USB. Coreboot is different though. I spoke with Starlabs whose computers run Coreboot, and apparently you can have the boot menu password. OTOH, Sys76’s Coreboot doesnt allow such things. I ask because i want to libreboot my T480, but the number 1 thing i worry is unauthorized USB boot. This one: libreboot.org/docs/linux/grub_hardening.html#grub… seems to only lock the ability to edit the grub entry freely, aka press “e” to change stuff when grub fails to boot.

Replies (13)

  • @hendrik@palaver.p3x.de 2026-09-08 16:29

    Not sure if I’m helping here. But sounds this could also be a X/Y problem… The way to make sure you don’t lose data is backups.

    Open ##4648972

  • I’m not sure I follow why this would be a big concern. If your drive is encrypted the worst they can do is wipe your data, which would require restoring a backup image. A hassle but it won’t give them access to your data.

    Open ##4648983

  • Just here for the comments, since I know of no way to disallow booting from removable media. Although I did recently come across a modern Lenovo laptop whose BIOS simply lacked the menu entry to switch boot order, boot device and anything like that…

    Open ##4648986

  • @cmnybo@discuss.tchncs.de 2026-09-08 18:19

    Setting a BIOS password doesn’t really do much good. Someone can just unplug the CMOS battery and the password will be cleared. Even if it was stored in flash, it could be removed by erasing it with a flash programmer and flashing a new BIOS.

    Open ##4649376

  • If someone has physical access to your laptop, can’t just turn it on and spill a glass of water on it?

    Open ##4649495

  • @Ooops@feddit.org 2026-09-08 20:34

    Nothing will prevent him from wiping your drive if he has physical access to your device. Sure you can use stuff like Secure Boot with your own custom keys to lock it. Then noone can indeed just boot it. Doesn’t stop that person from removing your drive and plugging it into another pc. Or from just smashing your disk to pieces. The same goes for stuff like a bios password. With physical access you can wipe that, too. It’s just a bit more work (or requires additional tools) than just an USB stick. In short: Yes, you can stop someone from just booting an USB stick and wipe you drive. But it doesn’t matter if he has other ways to do the same. Protection only works as a whole concept, Software won’t help you when physical security allows the device to be stolen. And seriously? Who cares if their stolen is wiped, smashed or drowning on the bottom of the ocean. It’s gone anyway. The actual protection for data is a) backups so you don’t lose them and b) encryption so nobody can read them.

    Open ##4649859

  • @TrollAccount69@lemmy.ml 2026-09-08 22:03

    I have a t480 here. It took me about five minutes to unscrew the bottom panel, remove the ssd and replace the bottom panel like before. Just make regular backups and practice restoring from them.

    Open ##4650122

  • @MonaySimpson@lemmy.ml 2026-09-08 22:07

    Reading the comments makes me wonder why BIOS passwords were even invented. Sounds like everyone is saying its a waste of time and to never use it if the biis supports it.

    Open ##4650126

  • @boredsquirrel@slrpnk.net 2026-09-09 01:00

    Idk if libreboot is coreboot+ a specific payload. But in edk2 which is used in dasharo you can set some UEFI boot targets and disable usb boot yes, of course also set a firmware password. There is also HEADS which is another payload of coreboot and can use a hardware security key to need to approve boot drives. Makes most sense with very stable distros like Qubes though as you dont constantly re-sign everything

    Open ##4650613

  • @monovergent@lemmy.ml 2026-09-09 02:05

    You could make it about equivalent to the protections afforded by the typical BIOS password, i.e. the attacker must first disassemble your laptop to reflash the flash chip or pull the hard drive. A grub.cfg like so would do, assuming everything in encrypted partitions: set prefix=(memdisk)/boot/grub set superusers="root" password_pbkdf2 root grub.pbkdf2.sha512.10000. cryptomount -u search.fs_uuid configfile ($root)/@rootfs/boot/grub/grub.cfg Assuming you boot directly to GRUB or locked out the SeaBIOS boot device selector, then GRUB will only ever look for a boot device matching your disk’s UUID; attempting to do anything else aside from entering the LUKS passphrase will prompt for the GRUB password. You’d still have your own recovery path by pressing Esc, entering your GRUB password, and dropping to the GRUB shell. Bonus points for patching the GRUB code so it doesn’t echo the UUID of your disk.

    Open ##4650848

  • @Eggymatrix@sh.itjust.works 2026-09-09 09:49

    Imo any attacker that has access to the hardware cannot be countered by software. There always is a badusb or sodder this here chip type attack possible against any attempt at locking up your pc. You can encrypt and backup, but any legends about tpm, bios passwords, weird hardware encryption features and keys are moot once an attacker can read what transits on the pcie or memory bus

    Open ##4653989

  • @DieserTypMatthias@lemmy.ml 2026-09-09 12:00

    Disable the boot menu and set a password on your UEFI before considering Libreboot.

    Open ##4655706

  • @nyan@sh.itjust.works 2026-09-09 18:27

    But what would prevent somebody plug in a USB with and just wipe my drive? If they have enough access to plug in a USB key, they have enough to smash the drive (or the entire machine) with a sledgehammer. Or move it to another machine that they control and wipe and reimage it there. (Shades of the xkcd with the crypto-nerd and the pipewrench: there’s always a non-technical, or less-technical, solution when it comes to security.)

    Open ##4658030