PureBoot, the high security boot process

The boot process, in computer hardware, forms the foundation for the security of the rest of the system. Security, in this context, means a “defense in depth” approach, where each layer not only provides an additional barrier to attack, but also builds on the strength of the previous one. Attackers do know that if they can compromise the boot process, they can hide malicious software that will not be detected by the rest of the system. Unfortunately, most of the existing approaches to protect the boot process also conveniently (conveniently for the vendor, of course) remove your control over your own system. How? By using software signing keys that only let you run the boot software that the vendor approves on your hardware. Your only practical choices, under these systems, are either to run OSes that get approval from the vendor, or to disable boot security altogether. In Purism, we believe that you deserve security without sacrificing control or convenience: today we are happy to announce PureBoot, our collection of software and security measures designed for you to protect the boot process, while still holding all the keys.

Good initiative.

7 Comments

  1. 2019-02-27 2:40 am
    • 2019-02-27 10:24 am
      • 2019-02-28 3:09 am
        • 2019-02-28 9:41 am
          • 2019-02-28 5:23 pm
          • 2019-03-01 1:31 pm
    • 2019-02-27 11:41 am