# Secure u-boot?

**URL:** <https://hub.mender.io/t/secure-u-boot/3971>\
**Category:** General Discussions\
**Tags:** secure-booting\
**Created:** [August 4, 2021, 4:59pm UTC](https://hub.mender.io/t/secure-u-boot/3971 "2021-08-04T16:59:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ikkysleepy](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ikkysleepy/32/156_2.png) [@ikkysleepy](https://hub.mender.io/u/ikkysleepy)\
**Post date:** [August 4, 2021, 4:59pm UTC](https://hub.mender.io/t/secure-u-boot/3971/1 "2021-08-04T16:59:56Z")

</div>

I saw this article and was wondering if the u-boot is secure or can it be hacked

> **[Security Flaws In Prominent EV Chargers Can Even Hack Your Account](https://fossbytes.com/security-flaws-in-ev-chargers-can-hack-account/)**
>
> Hackers can hijack driver's account and steal electricity.

Thanks,

- Jorge

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [August 4, 2021, 5:31pm UTC](https://hub.mender.io/t/secure-u-boot/3971/2 "2021-08-04T17:31:41Z")

</div>

Hi @ikkysleepy,

That’s not a simple yes-or-no question. What that article is specifically referring to is [Secure Boot](https://en.wikipedia.org/wiki/Unified_Extensible_Firmware_Interface#Secure_Boot) which is a mechanism to cryptographically verify that the images installed on your device have not been tampered with. It requires hardware support and the RpI just does not have that support, regardless of U-Boot or not.

If you have specific attack vectors you are looking to protect against, we may be able to provide more help.

Drew

---

<div class="post-metadata">

**Author:** ![ikkysleepy](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ikkysleepy/32/156_2.png) [@ikkysleepy](https://hub.mender.io/u/ikkysleepy)\
**Post date:** [August 4, 2021, 6:34pm UTC](https://hub.mender.io/t/secure-u-boot/3971/3 "2021-08-04T18:34:53Z")

</div>

I am just wondering if a hacker has physical access to our raspberry pi running mender, if they would be able to compromise the device and easily get the contents in the data partition or boot partition? If so, which other device has secure boot that mender can run on.

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [August 4, 2021, 9:19pm UTC](https://hub.mender.io/t/secure-u-boot/3971/4 "2021-08-04T21:19:41Z")

</div>

Secure Boot won’t help with the privacy of your images. It ensures that the devices won’t run modified code but it does nothing to protect against viewing of the files. It’s even easier with Raspberry Pi since it uses a removable SD Card, all the attacker has to do is remove the card and put it in their laptop so see the files from your system.

To protect against that you likely need full disk encryption. But you have to first determine how to get the passphrase to unlock the encryption entered at boot. I assume asking your device users to type in a passphrase on boot is not a viable solution. Presumably some kind of on board security chip could provide a passphrase but that requires custom hardware development.

Drew

---

<div class="post-metadata">

**Author:** ![ikkysleepy](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/ikkysleepy/32/156_2.png) [@ikkysleepy](https://hub.mender.io/u/ikkysleepy)\
**Post date:** [August 4, 2021, 9:40pm UTC](https://hub.mender.io/t/secure-u-boot/3971/5 "2021-08-04T21:40:35Z")

</div>

Looks like I went down the rabbit hole. The NVIDIA Jetson board looks like they have both secure-boot and disk encryption but not sure how mender will integrate into this board. Anyways, one day we will have encryption at rest and in transit. I’ll keep digging into one of those boards and seeing how to encrypt the data in the partition. Thanks.

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [August 4, 2021, 9:53pm UTC](https://hub.mender.io/t/secure-u-boot/3971/6 "2021-08-04T21:53:34Z")

</div>

Excellent. Please report back with any progress or issues.

Drew
