Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think there are two things being conflated here:

- the "shim" bootloader: https://wiki.ubuntu.com/UEFI/SecureBoot/Testing#Shim_bootloa... - it's important that this can't be used to boot a Windows that thinks it's secure but isn't.

- the "lockdown" patches you refer to. The goal of those is to maintain the attestation that the running kernel code is the code that was loaded through a signature chain. If you can modify the kernel at runtime, obviously the attestation has to be invalid.

I don't think it's impossible to boot Windows from Linux, but doing so should result in Windows detecting that it's in insecure/unsigned mode.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: