no, BIS keys are computed from device_key which only requires secure_boot_key which lives in fuses and tsec_key which is derived from burned-in hardware secrets. neither of these are changeable.Yes ofc the keys are in the hw itself. I thought biskeydump worked based off the NAND to pull keys from prodinfo/(f), rather than the mobo/etc.








