I understand LUKs can be used to encrypt your data. But what would prevent somebody plug in a USB with and just wipe my drive?

On traditional BIOS like Lenovo, HP, Dell and even Framework you can set a supervisor password that locks the boot menu. So nobody can boot from the USB.

Coreboot is different though. I spoke with Starlabs whose computers run Coreboot, and apparently you can have the boot menu password. OTOH, Sys76’s Coreboot doesnt allow such things.

I ask because i want to libreboot my T480, but the number 1 thing i worry is unauthorized USB boot.

This one: https://libreboot.org/docs/linux/grub_hardening.html#grub-password

seems to only lock the ability to edit the grub entry freely, aka press “e” to change stuff when grub fails to boot.

  • monovergent@lemmy.ml
    link
    fedilink
    arrow-up
    2
    ·
    edit-2
    2 days ago

    You could make it about equivalent to the protections afforded by the typical BIOS password, i.e. the attacker must first disassemble your laptop to reflash the spi chip or pull the hard drive. A grub.cfg like so would do, assuming everything in encrypted partitions:

    set prefix=(memdisk)/boot/grub
    set superusers="myuser"
    password_pbkdf2 myuser grub.pbkdf2.sha512.10000.<your hashed password>
    cryptomount -u <UUID of LUKS container>
    search.fs_uuid <UUID of the root filesystem under LUKS container> root cryptouuid/<UUID of LUKS container>
    configfile ($root)/@rootfs/boot/grub/grub.cfg
    

    Assuming you boot directly to GRUB or locked out the SeaBIOS boot device selector, then GRUB will only ever look for a boot device matching your disk’s UUID; attempting to do anything else aside from entering the LUKS passphrase will prompt for the GRUB password. You’d still have your own recovery path by pressing Esc, entering your GRUB password, and dropping to the GRUB shell. Bonus points for patching the GRUB code so it doesn’t echo the UUID of your disk.

    No, it isn’t bulletproof against physical access. But yes, I had the same question you did when starting out with coreboot and this was the solution I came up with.