From: Ahmad Fatoum <[email protected]> Any checks that generic barebox code currently does at update time are meant to reduce the likelihood of bricking a board and not as a security measure. Spell that out.
Signed-off-by: Ahmad Fatoum <[email protected]> --- Documentation/user/security.rst | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/Documentation/user/security.rst b/Documentation/user/security.rst index a618c05b1102..b204e6df8d23 100644 --- a/Documentation/user/security.rst +++ b/Documentation/user/security.rst @@ -56,6 +56,17 @@ fusing for both HABv4 and AHAB. touch the subset of fuses relevant to most users. It's up to the integrators to fuse away unneeded functionality like USB recovery or JTAG as needed. +Any verified boot setup that doesn't ensure that barebox was correctly signed +before execution is thus fundamentally flawed. A corollary to this is that +it's not enough to restrict the ways that barebox can be updated: An attacker +can often overwrite barebox without its knowledge, via physical access or +after having booted into the OS. barebox's signature being validated by the +previous boot stage is thus paramount. + +Specifically, the checks :ref:`barebox update <update>` performs on an image, +e.g. that it targets the right board, exist to reduce the risk of bricking +the board and can be skipped with ``-f``. They are not a security measure. + Ensuring the barebox devicetree is verified ------------------------------------------- -- 2.47.3
