System Details
- Device: bluebird
- OS: gentoo
- Firmware Type: UEFI Full ROM
- Firmware Version: N/A
- Internal storage type: eMMC
Summary of the Issue
I want to safely re-enable firmware write-protection on the chromebook for security purposes. I do not want to brick the chromebook in the process of doing this.
Also mrchromebox docs seem to suggest that even reenabling firmware write-protect doesn’t actually protect the firmware?
What will happen if I reconnect the suzyqable, and echo “wp enable” to the device node? Has anyone tried this before, and if so what were the results?
Another option is using the TPM for measured boot, I can’t seem to find any information about using the TPM to do this though.