Re: The Achilles Heel Of Secure Boot: Certificate Revocation

[email protected] (Scott Dorsey)
Newsgroups comp.misc
Organization Former users of Netcom shell (1989-2000)
Message-ID <[email protected]>
Lawrence =?iso-8859-13?q?D=FFOliveiro?=  <[email protected]> wrote:
>On Wed, 15 Jul 2026 12:20:09 -0000 (UTC), John McCue wrote:
>
>> IMO I always believed this is a ploy by Microsoft to lock down PCs
>> similar to what is going on with Smart Phones. But so far it has
>> failed due to pushback by various Linux Companies. If Linux was at
>> the point it was in the 90s, I think M/S would have succeeded.
>
>There is a genuine risk from attackers getting physical access to the
>machine -- Secure Boot was an attempt to defend against this sort of
>thing.

I think the very idea of trying to block an attacker with physical
access is probably misguided.  There are some applications for which it
may actually be useful but there are far more systems where availability
is as or more important than confidentiality.

>But you are right in that Microsoft’s implementation has been
>typically poorly managed and riddled with holes.

I think the concept is a bad one, and I think that invariably you are going
to have a single point of failure which is bad.  Having it be microsoft is
just worse.
--scott
-- 
"C'est un Nagra. C'est suisse, et tres, tres precis."
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.