Supply Chain Attacks
UEFI Secure Boot after BlackLotus and PKfail: what the trust chain still assumes
Secure Boot was designed to keep untrusted code from running before the operating system, but its trust anchors live in firmware that OEMs control and sometimes leak. BlackLotus and PKfail exposed the gap between the spec and the deployment.
May 12, 20267 min read