by thops
Mon Apr 16, 2018 11:11 pm
Forum: Firmware Security
Topic: Read-only variable
Re: Read-only variable

The UEFI spec already has provisions for making a variable inaccessible after BDS, just don't use the EFI_VARIABLE_RUNTIME_ACCESS attribute. This functionality is specifically about protecting a variable from 3rd party code that is run during (or after) BDS. If your variable needs BDS write access, ...