Bradly_Jeff RemoveThis @yahoo.com wrote:
> Hi All,
>
> I'm looking for a way to permanently disable reflashing of the bios.
> I have several platforms, not a specific vendor or series.
>
> I thought of removing the leg incharge of writing to the flash, but
> it's not possible, since in some flashes, it's used for other commands
> besides write/erase commands.
>
> I heard there is a way to disable reflashing through the motherboard,
> but didn't find info about it.
>
> Any suggestions how to permanently disable reflashing?
>
> Jeff.
>
Find a blank BIOS chip that is OTP (one time programmable).
These are used for devices where the manufacturer doesn't plan
on doing field upgrades. If soldered in place, so much the better.
(No temptation to swap out the BIOS chip, with an erasable
one.)
Now, what is the problem with this concept ? The flash chip is
not immutable. The DMI and ESCD areas of the BIOS chip, are
updated every time new hardware is added or removed from the
computer. On some BIOS designs, there are also a couple 2KB
microcode caches, for the microcode patch to the processor.
So the BIOS can write to certain areas of the chip, by itself.
If a machine has a stable configuration, I suppose you can
make a copy of the current contents of the flash, and put them
in an OTP. But I bet before long, the user will be complaining
about some error message that pops up during POST. So using
an OTP might not be the perfect solution. Some testing required...
Paul
>> Stay informed about: Preventing Bios Flash Reflashing Permanently