Hi, you probably saw this flaw that seems to be present on all Dell
machines >= 2009.

https://www.dell.com/support/kbdoc/000186019/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-insufficient-access-control-vulnerability

it is not entirely clear if BIOS itself is flawed, but
 - the phrase " insufficient access control vulnerability"
 - a new BIOS update on April 27
suggest that a bit. Do you have some more detailed information? If so,
it touches many qubes users as well, which brings me to a more general
question:  Updating BIOS seems, generally, a security nightmare. Running
untrusted software from an untrusted OS on an USB-key enhances
likelihood of an evil-maid attack,  and, worse,  you are the maid !

I am curious on your comments / help suggestions.  Best,

--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/aac5d82a-ffb6-5acc-ae71-86090b2e1334%40web.de.

Reply via email to