you are viewing a single comment's thread
view the rest of the comments
[–] 8 points 2 months ago (3 children)

Problem being, of course, that you can add more certificates, but you can't revoke the original M$ one. And since it's vulnerable and you can't get rid, then these exploits still work and there's nothing you can do to stop it.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 15 points 2 months ago*

    Computers shouldn't come with Microsoft keys preinstalled to begin with (or an operating system for that matter). Microsoft being able to have Windows preinstalled on the vast majority of non-Apple PCs is how they gained their monopoly in the first place.

  • source
  • parent
  • [–] 2 points 2 months ago

    On some systems you can clear all secure boot keys, including Microsoft's, then provision your own and sign your bootloader or kernel with it. Windows cannot boot from such systems.

  • source
  • parent