Hey guys, I've been looking a little into PC security lately and enabled Secure Boot on my Laptop.
It's a good thing because it assures me that the software booting is not malware (it's actually quite nuanced but let's stick to this assumption for the sake of my topic).
My concern now is: How do I know that noone resettet the UEFI settings, disabled Secure Boot and installed some malware which looks and behaves exactly like my OS?
The only protection I can think of is the UEFI not allowing a complete factory reset by setting a password, which cannot be reset. But I am unable to find good information on this topic. Is there an overview web site of common UEFI manufacturers/versions and their reset options? Searching for this topic revealed that several UEFIs have actual backdoor admin passwords. Are there any vendors who clearly state that their UEFI password protection cannot be circumvented?
Thanks for your thoughts!