From: Ahmad Fatoum <a.fatoum@pengutronix.de>
To: barebox@lists.infradead.org
Cc: Ahmad Fatoum <a.fatoum@barebox.org>
Subject: [PATCH 07/11] Documentation: security: document the barebox update attack surface
Date: Mon, 28 Sep 2026 13:27:02 +0200 [thread overview]
Message-ID: <20260928112731.1271094-8-a.fatoum@pengutronix.de> (raw)
In-Reply-To: <20260928112731.1271094-1-a.fatoum@pengutronix.de>
From: Ahmad Fatoum <a.fatoum@barebox.org>
Any checks that generic barebox code currently does at update time are
meant to reduce the likelihood of bricking a board and not as a security
measure. Spell that out.
Signed-off-by: Ahmad Fatoum <a.fatoum@barebox.org>
---
Documentation/user/security.rst | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/Documentation/user/security.rst b/Documentation/user/security.rst
index a618c05b1102..b204e6df8d23 100644
--- a/Documentation/user/security.rst
+++ b/Documentation/user/security.rst
@@ -56,6 +56,17 @@ fusing for both HABv4 and AHAB.
touch the subset of fuses relevant to most users. It's up to the integrators
to fuse away unneeded functionality like USB recovery or JTAG as needed.
+Any verified boot setup that doesn't ensure that barebox was correctly signed
+before execution is thus fundamentally flawed. A corollary to this is that
+it's not enough to restrict the ways that barebox can be updated: An attacker
+can often overwrite barebox without its knowledge, via physical access or
+after having booted into the OS. barebox's signature being validated by the
+previous boot stage is thus paramount.
+
+Specifically, the checks :ref:`barebox update <update>` performs on an image,
+e.g. that it targets the right board, exist to reduce the risk of bricking
+the board and can be skipped with ``-f``. They are not a security measure.
+
Ensuring the barebox devicetree is verified
-------------------------------------------
--
2.47.3
next prev parent reply other threads:[~2026-09-28 11:29 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 11:26 [PATCH 00/11] Documentation: define a barebox threat model Ahmad Fatoum
2026-09-28 11:26 ` [PATCH 02/11] Documentation: security: clarify development key insecurity Ahmad Fatoum
2026-09-28 11:26 ` [PATCH 03/11] Documentation: security: require signature verification to be pinned Ahmad Fatoum
2026-09-28 11:26 ` [PATCH 04/11] Documentation: security: document trust for builtin devicetree Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 05/11] Documentation: security: clarify the environment section Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 06/11] Documentation: security: describe shell and environment as trust boundary Ahmad Fatoum
2026-09-28 11:27 ` Ahmad Fatoum [this message]
2026-09-28 11:27 ` [PATCH 08/11] Documentation: security: update for barebox dm-verity support Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 09/11] Documentation: security: add anchors for the different sections Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 10/11] Documentation: define a barebox threat model Ahmad Fatoum
2026-09-28 11:27 ` [PATCH 11/11] README, SECURITY.md: link the threat model and security considerations Ahmad Fatoum
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928112731.1271094-8-a.fatoum@pengutronix.de \
--to=a.fatoum@pengutronix.de \
--cc=a.fatoum@barebox.org \
--cc=barebox@lists.infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox