Also, there's no breaking involved as there's no signature anywhere, it's a reasonably simple mod. For example, re-enabling CPU undervolting seems to be impossible in modern ThinkPads because the UEFI firmware is signed.
Also, there's no breaking involved as there's no signature anywhere, it's a reasonably simple mod. For example, re-enabling CPU undervolting seems to be impossible in modern ThinkPads because the UEFI firmware is signed.
Why can't you upload your own private key in the new bios payload, like you can for SecureBoot?
Everything is sitting in a flash chip. Some parts may be RO, but it can be replaced by another chip if you can't tweak it directly with flashrom.
Vendors burn a key into the system which prevents loading an unsigned BIOS. This is a one-time-programmable fuse (OTP fuse) and part of Intel BootGuard protections.
You get a laptop with _fused burned_ to prevent loading other firmware to your device. Booting won't work if you load a replacement SPI chip with anything but a vendor-signed firmware.