logoalt Hacker News

noisem4kerlast Tuesday at 10:41 PM1 replyview on HN

Yes. The PCR state after booting won't match that of the regular system, so the TPM will refuse to give up the key.


Replies

evan_a_ayesterday at 5:03 PM

This is contingent on the sealing policy including PCRs that would change as a result of booting a different operating system, like PCR 11, which, when booting a UKI, contains those measurements. Only sealing against PCR 7 would allow this attack, since the default platform secure boot policy would not need to change.