Re: The Achilles Heel Of Secure Boot: Certificate Revocation
[email protected] (Scott Dorsey)
| Newsgroups | comp.misc |
|---|---|
| Organization | Former users of Netcom shell (1989-2000) |
| Message-ID | <[email protected]> |
Lawrence =?iso-8859-13?q?D=FFOliveiro?= <[email protected]> wrote: >On Wed, 15 Jul 2026 12:20:09 -0000 (UTC), John McCue wrote: > >> IMO I always believed this is a ploy by Microsoft to lock down PCs >> similar to what is going on with Smart Phones. But so far it has >> failed due to pushback by various Linux Companies. If Linux was at >> the point it was in the 90s, I think M/S would have succeeded. > >There is a genuine risk from attackers getting physical access to the >machine -- Secure Boot was an attempt to defend against this sort of >thing. I think the very idea of trying to block an attacker with physical access is probably misguided. There are some applications for which it may actually be useful but there are far more systems where availability is as or more important than confidentiality. >But you are right in that Microsoft’s implementation has been >typically poorly managed and riddled with holes. I think the concept is a bad one, and I think that invariably you are going to have a single point of failure which is bad. Having it be microsoft is just worse. --scott -- "C'est un Nagra. C'est suisse, et tres, tres precis."