4 ms·
FWIW Secure Boot has its own blacklist, called the Revoked Signatures or Forbidden Signatures database or dbx, though I don't know if and how it is actually use
by hackuser 9y ago
FWIW Secure Boot has its own blacklist, called the Revoked Signatures or Forbidden Signatures database or dbx, though I don't know if and how it is actually used.
> old windows kernels can't be blacklisted because then people's install media that they might have paid for would stop working.
I understand the theory, but are you sure that is true in practice? There also could be a workaround (such as disabling Secure Boot for the install).
- my123 9y agoMicrosoft uses STLs, which are flashed into UEFI variables. (had other glaring issues though, Secure Boot policies weren't checked with DBX or the STLs... which made it a real issue)
- poizan42 9y agoThere was the secure golden key boot exploit last year[0]. In the conclusion they also points out that Microsoft can't revoke the affected bootmgr versions: > Either way, it'd be impossible in practise for MS to revoke every bootmgr earlier than a certain point, as they'd break install media, recovery partitions, backups, etc. [0]: https://rol.im/securegoldenkeyboot/ https://rol.im/securegoldenkeyboot/