you are viewing a single comment's thread
view the rest of the comments
[–] 1 point 2 months ago

Secure boot does have a revocation mechanism (It's literally how this issue has been mitigated) though.

You can not only load in allowed signatures, you can also load in disallowed ones so even properly signed binaries will get rejected.

  • source
  • parent