39

I understand LUKs can be used to encrypt your data. But what would prevent somebody plug in a USB with and just wipe my drive?

On traditional BIOS like Lenovo, HP, Dell and even Framework you can set a supervisor password that locks the boot menu. So nobody can boot from the USB.

Coreboot is different though. I spoke with Starlabs whose computers run Coreboot, and apparently you can have the boot menu password. OTOH, Sys76's Coreboot doesnt allow such things.

I ask because i want to libreboot my T480, but the number 1 thing i worry is unauthorized USB boot.

This one: https://libreboot.org/docs/linux/grub_hardening.html#grub-password

seems to only lock the ability to edit the grub entry freely, aka press "e" to change stuff when grub fails to boot.

you are viewing a single comment's thread
view the rest of the comments
[-] MonaySimpson@lemmy.ml 1 points 1 day ago

Reading the comments makes me wonder why BIOS passwords were even invented.

Sounds like everyone is saying its a waste of time and to never use it if the biis supports it.

[-] Majestic@lemmy.ml 9 points 1 day ago

BIOS boot passwords were from another era with different needs and assumptions. In controlled access environments they can still have an impact if you have a proper chassis that has locks on it preventing removal of drives. Most normal people don't possess such business class chassis. The scenario was a business environment with security teams, other employees, supervisors and locks that while you could cut them with heavy equipment you'd be noticed doing so. In terms of preventing a team of thieves breaking in with power tools and stealing things true it never was meant to prevent that. It's more authorization and access control within an organization. The idea being perhaps the CEO's machine or a special machine for accessing sensitive devices would be physically locked and have such a password installed as another layer of security that couldn't be bypassed surreptitiously.

Additionally back in the day these BIOS boot passwords were paired with chassis intrusion alarms which went off every subsequent boot if the chassis was opened thanks to a sensor and the only way to clear that alarm was logging into the BIOS with an admin password.

Your gaming computer BIOS supports neither of these nor does your gaming motherboard have a chassis intrusion connector nor does your gaming case come with support for such a device.

But it was never about preventing data destruction even in these cases. It was more preventing access and making any such access more time consuming and likely to trip alarms to allow a response including evaluation of compromise by professionals.

If you want to protect your data make backups. If you want it well protected against determined parties who want to destroy all copies and/or thieves then locate a copy off-premises. If you can't do that at least locate a copy within a bolted down safe.

this post was submitted on 08 Sep 2026
39 points (100.0% liked)

Linux

67493 readers
269 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 7 years ago
MODERATORS