Re: The Achilles Heel Of Secure Boot: Certificate Revocation
Richard Kettlewell <[email protected]>
| Newsgroups | comp.misc |
|---|---|
| Organization | terraraq NNTP server |
| Message-ID | <[email protected]> |
Lawrence D’Oliveiro <[email protected]> writes: > John McCue wrote: >> IMO I always believed this is a ploy by Microsoft to lock down PCs >> similar to what is going on with Smart Phones. But so far it has >> failed due to pushback by various Linux Companies. If Linux was at >> the point it was in the 90s, I think M/S would have succeeded. Microsoft’s own specifications have continuously included a requirement to support disabling secure boot. > There is a genuine risk from attackers getting physical access to the > machine -- Secure Boot was an attempt to defend against this sort of > thing. UEFI Secure Boot is not a defence against a physically present attacker. On a typical configuration it’s straightforward to disable it without authentication, just physical presence. You _can_ tighten that up a bit (e.g. require a password for firmware access), but (on PC platforms) the value of doing so is negligible. If you want to resist physically present attackers then you need a lot more than secure boot. -- https://www.greenend.org.uk/rjk/