Hacker News new | past | comments | ask | show | jobs | submit login

> Sure temporary disabling secure boot for making Linux installs easier is nice, but not required for functionality.

For as long as Microsoft deigns to allow the signed shim to boot.

Microsoft is the only key authority allowed by the main PC manufacturers. If you wish to become a key authority yourself, to allow your OS to boot on Secure Boot enabled devices without asking the end user to install additional keys (note: some devices may not allow this), then you must go to the OEMs individually and petition to be added to their key authority list. Prices from the OEMs that allow this are in the millions of dollars.




> - not being able to set a custom platform key

In which case this doesn't matter. (i.e. if you can set a custom platform key)

Also Microsoft would not only need to stop signing shims but revoke all existing signatures.


it's very, very easy for them revoke the signatures (the "dbx" variable)

if you run windows update it's happened dozens of times on your machine without you realising it

for example: they blacklisted a load of linux bootloaders last year due to the boothole vunerability

as a result: on a machine that's run windows update you now can't boot pre-2021 linux (both existing installs and installation media)

they could be nefarious very easily if they wanted to:

1. refuse to sign new builds

2. wait for the inevitable exploits

3. block all bootloaders capable of booting Linux as a security measure


Through in practice they can't really do so.

Or they already would have done it years ago.

What is holding them back is regulatory oversight, and the fear of it.

So if they ever do so, it's not a fault of "secure boot" and similar, but 100% the fault of politicians seriously messing up their job.

EDIT: You can also blame Apple, for constantly pushing in a direction where such regulatory oversight is removed. (END EDIT)

IMHO Secure Boot and TPM are features I want in my system if properly implemented. A laptop not supporting some form of secure boot and TPM would be for me a reason for not buying it. (Through being able to use custom platform keys is also a must have for me.)


The "Other OS" feature of your PC has been disabled because of security issues.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: