logoalt Hacker News

madducitoday at 3:26 PM3 repliesview on HN

Because this can end very badly. It is a new surface to attack


Replies

M95Dtoday at 3:36 PM

Exactly! It's actually great! More ways to jailbreak stuff.

eqvinoxtoday at 3:52 PM

Why is it a new surface? Either you can run UEFI code, or you can't. Attacking the JS interpreter itself is unrealistic IMHO, it's the poorly written JavaScript running on top of this that might open new surfaces of attack. But other UEFI code is mostly written in C or C++, so let's call that a wash?

yjftsjthsd-htoday at 3:36 PM

Maybe? What's your threat model?