Hacker News new | past | comments | ask | show | jobs | submit login

They sell this vendor lock-in "feature" as enhanced security?





Yes. It keeps the board from booting if the firmware is replaced with a version not signed by the board manufacturer (i.e. so an attacker can’t replace it with a version that does nefarious things). Preventing CPU reuse in other boards is just an (unintentional?) side effect.

The cynic would say the security implications are the side effect, since selling more, new chips is the goal.

If that was the goal then the CPU would fuse on first boot for any manufacturer’s board, rather than being fused only by Dell boards.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: