▲ 256 ▼ Microsoft’s Secure Boot has been broken for a decade and no one noticed until now (www.welivesecurity.com) submitted 2 months ago by beep@piefed.world to c/technology@lemmy.world 63 comments fedilink hide all child comments cross-posted from: https://piefed.world/c/tech/p/1263218/microsofts-secure-boot-has-been-broken-for-a-decade-and-no-one-noticed-until-now
[–] evadersnack@sopuli.xyz 1 point 2 months ago (1 child) A PKI without a CRL will eventually become exploitable. permalink fedilink source parent hideshow 1 child comment replies: [–] The_Decryptor@aussie.zone 1 point 2 months ago Secure boot does have a revocation mechanism (It's literally how this issue has been mitigated) though. You can not only load in allowed signatures, you can also load in disallowed ones so even properly signed binaries will get rejected. permalink fedilink source parent
[–] The_Decryptor@aussie.zone 1 point 2 months ago Secure boot does have a revocation mechanism (It's literally how this issue has been mitigated) though. You can not only load in allowed signatures, you can also load in disallowed ones so even properly signed binaries will get rejected. permalink fedilink source parent