Secure boot protects the startup chain
Secure boot means each stage of starting up verifies the next before running it, so unauthorised firmware does not load.
It matters because anything that runs before the operating system can lie to everything above it. It is also only as good as the keys behind it and the process for updating them, which is where implementations usually fall down rather than in the concept.
More on IoT and embedded
- A default password scales into a fleet vulnerabilityOne word, printed a million times
- Physical access changes the embedded threat modelThe lid was the threat model
- Firmware updates are a long-term security promiseYou sold the box, you signed up for the years
- Device identity should be uniqueAll answering to one name
- Cloud shutdown can strand smart devicesThe strings came from elsewhere
- Sensors can be fooled without hacking softwareNo code was touched
