256
Found in the wild: The world’s first unkillable UEFI bootkit for Linux
(arstechnica.com)
This is a most excellent place for technology news and articles.
Attacks only machines running specific Ubuntu kernels and using specific boot methods. Plus no actual payload. This doesn't yet represent a real risk.
Where we'll be in ten years' time is unknowable, however. I think the Ars commentors who suggested going back to forcing jumper cap swaps or other hardware-mediated access requirements before overwriting the mobo's boot firmware might be on the right track, even if it's inconvenient for large corporate deployments. It's normal for security and convenience to pull in opposite directions, and sometimes you just have to grin and bear it.