For those using the coreboot, how do you update it? Do you use the external flashing option (using a Raspberry Pi, etc.) or do you use the internal flashing method?
In case of doing the internal flashing method, do you guys apply the commands on the guide above in dom0?
So um, would you describe the internal flashing process as useful/easy? It seems like I would need to unlock the IFD during my FIRST flashing of coreboot.
The process is the same, but you don’t need to take the computer apart and interface with the chip.
I think I depend a lot on the model you have, how useful it is. On the X220 or X230 you just need to open the back side to get to the chip, but the T models you need to take completely apart.
I’m personally not overly worried about it, my threat model mainly focuses on what someone can do over the internet. I think it’s very unlikely someone is going to break into my house just to flash the firmware in my desktop PC.
Coreboot supports vboot where you can sign the firmware, then you get a warning if the firmware loaded doesn’t match the signing key.
I’m using Dasharo and I believe it has vboot enabled.