Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Agreed, but typically /boot isn't automounted when it's a separate partition, which means they would need a root-access compromise already.


Hetzner allows to netboot any server via admin panel. After booting into recovery os, you can modify unencrypted parts as you wish.


They can replace the booting kernel. Unless you use SecureBoot, TPM or some such thing, there is no way to protect against that (assuming that the attacker has access to the shut-down system at one point and you boot it later).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: