On Wed, Dec 6, 2023 at 1:36 AM Mate Kukri <email address hidden> wrote:
>
> A fairly simple and non-invasive fix I could PoC would be to patch EDK2
> to only allow launching the Shell if SecureBootEnabled==0 ||
> SecureBoot==0 || SetupMode==1.
>
> That way key enrollment could stay identical for now, users with SB
> disabled would still have the shell available, and theoretically
> (fingers crossed) we'd get away with a small patch.
On Wed, Dec 6, 2023 at 1:36 AM Mate Kukri <email address hidden> wrote: ed==0 ||
>
> A fairly simple and non-invasive fix I could PoC would be to patch EDK2
> to only allow launching the Shell if SecureBootEnabl
> SecureBoot==0 || SetupMode==1.
>
> That way key enrollment could stay identical for now, users with SB
> disabled would still have the shell available, and theoretically
> (fingers crossed) we'd get away with a small patch.
Yes, I agree that would be ideal. Is there a channel open with /github. com/tianocore/ tianocore. github. io/wiki/ Reporting- Security- Issues
upstream on this matter where we could discuss such a patch? If not,
shall we open a security bug in their bugzilla?
https:/