Would you help me improve the security of my device? currently it is HSI:0


For information on the contents of this report, see https://fwupd.github.io/hsi.html

Can you tell us with which app you make this test?

Please put a:

your command

to get an English output.

$ fwupdmgr security

Host Security ID: HSI:0! (v1.9.7)

✔ BIOS firmware updates:         Enabled
✔ TPM empty PCRs:                Valid
✔ TPM v2.0:                      Found
✔ UEFI bootservice variables:    Locked
✔ UEFI platform key:             Valid
✔ UEFI secure boot:              Enabled
✘ Fused platform:                Unknown
✘ Supported CPU:                 Invalid

✔ IOMMU:                         Enabled
✔ TPM PCR0 reconstruction:       Valid
✘ Platform debugging:            Unknown
✘ SPI write protection:          Unknown

✘ Pre-boot DMA protection:       Disabled
✘ SPI replay protection:         Unknown
✘ Suspend-to-idle:               Disabled
✘ Suspend-to-ram:                Enabled

✘ Encrypted RAM:                 Unknown
✘ Processor rollback protection: Unknown

Runtime Suffix -!
✔ Linux kernel lockdown:         Enabled
✔ Linux swap:                    Encrypted
✔ fwupd plugins:                 Untainted
✘ Linux kernel:                  Tainted

This system has a low HSI security level.
 » https://fwupd.github.io/hsi.html#low-security-level

This system has HSI runtime issues.
 » https://fwupd.github.io/hsi.html#hsi-runtime-suffix

Host Security Events
  2023-10-15 04:12:15:  ✘ Kernel is tainted
  2023-10-10 20:04:34:  ✔ Kernel is no longer tainted
  2023-10-10 18:31:18:  ✘ Kernel is tainted
  2023-10-10 14:41:04:  ✔ Kernel is no longer tainted
  2023-10-10 02:36:40:  ✔ Intercambio de Linux changed: Unencrypted → Encrypted