2026-09-09 02:05 UTC
You could make it about equivalent to the protections afforded by the typical BIOS password, i.e. the attacker must first disassemble your laptop to reflash the flash chip or pull the hard drive. A grub.cfg like so would do, assuming everything in encrypted partitions:
set prefix=(memdisk)/boot/grub
set superusers="root"
password_pbkdf2 root grub.pbkdf2.sha512.10000.
cryptomount -u
search.fs_uuid
configfile ($root)/@rootfs/boot/grub/grub.cfg
Assuming you boot directly to GRUB or locked out the SeaBIOS boot device selector, then GRUB will only ever look for a boot device matching your disk’s UUID; attempting to do anything else aside from entering the LUKS passphrase will prompt for the GRUB password. You’d still have your own recovery path by pressing Esc, entering your GRUB password, and dropping to the GRUB shell. Bonus points for patching the GRUB code so it doesn’t echo the UUID of your disk.
Replies (0)
No replies.