Security when connecting autonomous BB to the Internet

Aaah - thanks: a rational answer to an irrational question.

Yet, completely true..

Unless you pay TI lots of money for the secure fuse version of the
am335x. As long as someone has physical access to the board, they can
make it boot.

Thus, the only logical secure physical solution, is in your
lock/case/etc design.

Regards,

heh, I was thinking more like put the beaglebone into a tamper proof case with only the Ethernet port exposed. It funny though what Robert said above was actually practiced in the 80’s for arcade PCBs. Although they limited themselves to “potting” proprietary circuits usually.

It is if there is nothing in the SD slot. All the button does is change the boot order not the boot options.

Yeah, I should have been more clear. I meant that the eMMC isn’t accessed before the SDCard so there was no modification to u-boot that would prevent access to the SDCard.

Regards,
John

Thanks to everybody that pitched in here - I see the error of my ways; after looking at the TI boot pages I see we are indeed at the mercy of TI’s boot rom.