I'm not in a situation where I have to defend myself all the time, at all costs. As long as I don't have a proprietary BIOS, anything beyond disk encryption and maybe stuff like grsec and the like is overkill.

So I don't see the point nor do I have the need for a GRUB password. It would be an amazing waste of time to get into my house, re-flash and go away just to hope getting my decryption passphrase (else, why not just take the whole computer anyway?).

I feel your answer assumes I defend propriety BIOS, but it's early, I'm already tired and I don't have the time to dig much further.

My point is that the suggested extra security is most likely extra burden since the probability for such an attack is so low.
Plus the user base is so small I doubt it's even worth the time and effort.

I mean you can harden your machine forever, it will never be safe unless you never turn it on. On that security spectrum (extreme but useless security to zero security but very useable): - GRUB password can be useful, but not that likely to actually be useful for most people. As you said, unwanted software reflashing would require root access. - Not being able to prevent software reflashing still allows for hardware reflashing, which is a highly unlikely scenario. There's no money in there, and too many risks.

Reply via email to