Git Product home page Git Product logo

Comments (3)

texhex avatar texhex commented on August 19, 2024

No, this can be bypassed, this is hard coded. Any change, that the BIOS sees as an decrease in security (e.g. turning SGX off) will trigger a PPI prompt. The other way around, e.g. activating SGX should go through directly.

You can turn of PPI, but this change will trigger an PPI prompt itself. Also, I would not recommend this at all, PPI is to prevent "under the hood" changes that might weaken your security settings without anyone noticing.

If you really, really need to get PPI out of your way, the only way would be to talk to your HP sales person if HP can deliver devices with custom BIOS settings (factory set to your defaults). But I believe they only offer this in some markets and require a minimum amount of devices orders.

from biossledgehammer.

jsnyder33 avatar jsnyder33 commented on August 19, 2024

I think you meant to say this can't be bypassed, right? Alright this makes sense, and I appreciate the quick response!

By any chance do you know if the BIOS can be updated if the Intel Software Guard Extensions (SGX) setting is set to "Software Control" instead of "Enabled"? I will test Monday in the lab but thought I'd ask just in case you're familiar with it.

from biossledgehammer.

texhex avatar texhex commented on August 19, 2024

Yes, you are right, this was an typo. Sorry. It should read: It can't be bypassed.

I'm not aware that there is any difference for the BIOS update process if the SGX setting is changed. However, we do not use SGX.

I could think that if SGX requires some sort of "activation" for a SGX enclave (key enrollment) and you try an BIOS update after this that also includes an fTPM update, there might be an additional prompt as most likely the enclave key will be deleted.

from biossledgehammer.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.