Re: The Achilles Heel Of Secure Boot: Certificate Revocation

Richard Kettlewell <[email protected]>
Newsgroups comp.misc
Organization terraraq NNTP server
Message-ID <[email protected]>
Lawrence D’Oliveiro <[email protected]> writes:
> John McCue wrote:
>> IMO I always believed this is a ploy by Microsoft to lock down PCs
>> similar to what is going on with Smart Phones. But so far it has
>> failed due to pushback by various Linux Companies. If Linux was at
>> the point it was in the 90s, I think M/S would have succeeded.

Microsoft’s own specifications have continuously included a requirement
to support disabling secure boot.

> There is a genuine risk from attackers getting physical access to the
> machine -- Secure Boot was an attempt to defend against this sort of
> thing.

UEFI Secure Boot is not a defence against a physically present attacker.
On a typical configuration it’s straightforward to disable it without
authentication, just physical presence.  You _can_ tighten that up a bit
(e.g. require a password for firmware access), but (on PC platforms) the
value of doing so is negligible.

If you want to resist physically present attackers then you need a lot
more than secure boot.

-- 
https://www.greenend.org.uk/rjk/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.