• Default Username@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    28
    arrow-down
    1
    ·
    edit-2
    8 hours ago

    I get why they do this, because downgrade attacks are a thing that are used to exploit devices remotely, but there are other ways to implement this, like what GrapheneOS does. Downgrading can also just be restricted to unlocked bootloaders as well via a software revocation list that gets deleted/bypassed upon unlocking.

    There is no good reason for devices to use efuses to block downgrades unless they are trying to restrict user freedom a la consoles.

    • Zak@lemmy.world
      link
      fedilink
      English
      arrow-up
      45
      ·
      7 hours ago
      • Reasonable: prevent downgrades when the bootloader is locked
      • Sketchy: prevent downgrades when the bootloader is unlocked
      • Unhinged: hard-brick the device when a downgrade is attempted