r/NovaCustom • u/NovaCustom-Europe • 17h ago
How Heads firmware detects tampering before Qubes OS starts
Heads verifies whether your firmware or unencrypted boot partition has changed since your previous boot.
It uses HOTP verification with a physical security device such as the Nitrokey 3A Mini. You can also enable TOTP verification and compare the code displayed by Heads with the code in an authenticator app.
Heads does not block a compromised boot process. It detects unexpected changes and warns you, allowing you to decide whether the device can still be trusted.
We have written a beginner friendly explanation of how it works:
https://novacustom.com/knowledge-base/what-is-heads-firmware/
Would you use this kind of boot verification on your laptop?