firmware anti-rollback is actively used since Pixel 6
This commit is contained in:
@@ -360,9 +360,9 @@
|
||||
OS, it can be detected with these features.</p>
|
||||
|
||||
<p>Verified boot verifies the entirety of the firmware and OS images on every
|
||||
boot. The public key for the firmware images is burned into fuses in the SoC
|
||||
at the factory. Firmware security updates can also update the rollback index
|
||||
burned into fuses to provide rollback protection.</p>
|
||||
boot. The public key for the firmware images is burned into fuses in the SoC at
|
||||
the factory. Firmware security updates also update the rollback index burned
|
||||
into fuses to provide rollback protection.</p>
|
||||
|
||||
<p>The final firmware boot stage before the OS is responsible for verifying
|
||||
it. For the stock OS, it uses a hard-wired public key. Installing GrapheneOS
|
||||
|
||||
Reference in New Issue
Block a user