I second this, usually bios updates are signed
you could always check if there is a signature with binwalk or smtg if it makes you feel safer
you could always check if there is a signature with binwalk or smtg if it makes you feel safer
Certificate in DER format (x509 v3)
SHA256 hash constants, little endian
Very interesting to dig around in the firmware, I even found the boot splash image. Definitely a time sink, but fun.