3 ms·
Does MSFT's approach make it harder to write rootkits? Doesn't that have value to their users? Is there a plausible alternative that protects their users to t
by kvb 14y ago
Does MSFT's approach make it harder to write rootkits? Doesn't that have value to their users? Is there a plausible alternative that protects their users to the same degree? If not, then even if it makes it harder for users to install Linux as a side effect (or primary effect, if you're feeling cynical), I don't understand why this behavior would be illegal.
- jerf 14y agoYes, yes, and yes respectively. Secure booting isn't necessarily a bad thing, but users must be in full control over their keys. Only the user can decide who the user trusts. If the default shipping state is that only the keys used by the currently-installed OS are valid, well, that's just the only sane default. But that's not how this is being done.
- kvb 14y agoIs that really an issue with Microsoft/UEFI/secure boot, or is the problem that OEMs aren't building firmware that does what you want?
- takluyver 14y agoWell, for ARM devices, Microsoft doesn't allow OEMs to provide a way to change the keys. For what it's worth, I think Microsoft are doing this for the security reasons they give. But I think they were well aware of the hurdle it would present to Linux distributions when they chose to do it.