manufacturers could add support for the new key by updating the KEK database
Oh right, the KEK database. They are literally trolling us aren't they.
manufacturers could add support for the new key by updating the KEK database
Oh right, the KEK database. They are literally trolling us aren't they.
Not if you disable it, "secure boot" is a joke anyway.
The actual problem is (and has been for a long time) the enormous amount of absolute trash-level uefi implementations.
Updating keys is easy. Alas... a lot of them are completely broken beyond repair and fail everything but running with the pre-installed keys, which includes updating (or adding new) keys (bonus points for the really screwed up devices that even sign some their own hardware with the pre-installed MS keys thus bricking themselves if those keys are changed).
not a problem
If you use linux and are dependant on M$, youre doing it wrong
all 14 comments