5 ms·
Source: https://github.com/mjg59/shim https://github.com/mjg59/shim The issue is getting binaries you build signed, I guess (i.e.: Debian can't build Shim and
by randallu 14y ago
Source:
https://github.com/mjg59/shim https://github.com/mjg59/shim
The issue is getting binaries you build signed, I guess (i.e.: Debian can't build Shim and get a signed binary at the end, so having source isn't important to them; however if you want to contribute fixes, etc, then presumably you can develop on a machine with your own certificate installed and then RedHat can pay to get a new Shim build signed by Microsoft).
- gnosis 14y ago"The issue is getting binaries you build signed" How is the shim binary signed? "Debian can't build Shim and get a signed binary at the end" Why can the shim's author sign his own binary, but Debian can't sign theirs?
- mjg59 14y ago"How is the shim binary signed?" I paid Symantec $99, sent them a notarised copy of my ID, created a Microsoft sysdev account, uploaded the binary to Microsoft, waited a couple of days and got a signed one back. "Why can the shim's author sign his own binary, but Debian can't sign theirs?" Debian could do the same, but could all their users? Will Microsoft sign binaries for someone in Syria? That kind of thing is important to Debian, and it's one of the things that distinguishes them from the vast majority of other Linux distributions.
- gnosis 14y agoWhy does Microsoft have to be involved in the signing process? After all, you're not buying the computer from them. Can't there be some sort of independent signing authority? In fact, why couldn't the user just sign and install his own code without involving any third party at all? This whole "secure boot" system seems really poorly conceived, unless its purpose is to take power away from the user who owns the computer and give it to a central authority.
- mjg59 14y agoThere could be an independent signing authority providing that (a) they could provide some incentive to all hardware vendors to ship their keys and (b) there was someone actually competent and willing to be that independent signing authority. For Microsoft, this is just an extension of the Windows driver signing program - they already had most of the infrastructure in place, so there was little additional expense involved in handling Secure Boot as well. And Microsoft certainly have the means to "encourage" vendors to ship with their keys, since they can withhold the Windows logo program funding from vendors otherwise.
- yuhong 14y agoI suggested on twitter to just transfer Microsoft's keys if possible.
- mjg59 14y agoThere's still the cost of managing it (you're looking at $millions) - it's something that various parties have looked into, and then decided against. It's also unclear that having a third-party holder would actually be any better. So far Microsoft have behaved far more reasonably than you might expect, and what problems there have been can be chalked up to large company rather than malice. I understand why people don't want to trust Microsoft, but I don't currently see any evidence that they're misusing their powers here.
- gcb 14y agowait, so can't we compile, generate the same binary and use the key as the checksums would be the same?
- beagle3 14y agoSupposedly it's only $100; I'm happy to put $100 every few months so Debian can sign whatever updates they make, if they decide to go that way. I'm sure the community can collect $1,000/year, which will be more than enough for Debian's update. They might refuse to do it on an ideological basis, though.