How can I investigate HP sure start triggering warnings?

485    Asked by Amitraj in Cyber Security , Asked on Mar 22, 2022

The following question belongs more to the HP forums but unfortunately I am not gaining any traction there. Please move the question to another SE if it's off topic for this community.


Recently I've started receiving the following BIOS interruption & message at each boot:

"HP Sure Start detected an unauthorised change to the Secure Boot Keys. The key was restored automatically and there is no further action required. The repeated occurrence of this problem indicates a security problem should not be ignored."

See screenshot at the bottom.

I have no idea what is causing this warning. I recall recently updating Zoom and perhaps a routine Ubuntu update, but nothing else.

I am using the laptop for security critical interactions so I want to make sure I understand what is causing this and how to get to the bottom of it.

Any idea how I could investigate what is changing Secure Boot keys and why? What exactly could be the trigger for such a warning? How can this be investigated further and resolved?

Answered by Amit raj

Regarding HP sure start trigger warnings, I think it looks like something is updating your trusted keys in UEFI (if you are using BIOS or "legacy", please switch to UEFI). This might come from the Ubuntu OS (or not). Have you updated the firmware of your motherboard? Have you set an admin password on your BIOS/UEFI? If not, please do both then come back if this did not solve your issue. Also, this question might be more suited to a chat on the DMZ, or should be asked on superuser.com or unix.stackexchange.com.



Your Answer

Interviews

Parent Categories