Re: The Achilles Heel Of Secure Boot: Certificate Revocation
[email protected] (Scott Dorsey)
| Newsgroups | comp.misc |
|---|---|
| Organization | Former users of Netcom shell (1989-2000) |
| Message-ID | <[email protected]> |
Richard Kettlewell <[email protected]> wrote: >In contrast I’m aware of platforms where the firmware directly verifies >and loads a kernel and base OS image; they have no intermediate shims or >boot loaders to contain vulnerabilities at all. Much easier to secure, >but it doesn’t make for an easily ‘tinkerable’ platform. This is the sane and reasonable approach. The PC was filled with the legacy junk left over from the era of Basic-In-ROM and the mess that is legacy bios. But the move to EFI didn't simplify things, didn't make debugging more easier, and didn't speed boot times. It made all of these things worse. I miss machines with straightforward monitor roms. Press "B" and it seeks to address zero of the selected device, loads 256 bytes, and runs them. When EFI fails, figuring out what is going on can be quite an adventure even if you're running linux without secure boot being employed. --scott -- "C'est un Nagra. C'est suisse, et tres, tres precis."