Comment 2 for bug 2040139

Revision history for this message
Mate Kukri (mkukri) wrote :

setting UEFI variables isn't the main issue, the main issue is that the shell can modify arbitrary physical memory.

building it out should solve this as there are no signed shells out there anymore, and the only reason it can run under secure boot is because its built into the firmware.