all 14 comments

sorted by: hot top controversial new old
[–] 24 points 1 year ago

manufacturers could add support for the new key by updating the KEK database

Oh right, the KEK database. They are literally trolling us aren't they.

  • source
  • [–] 19 points 1 year ago (3 children)

    Not if you disable it, "secure boot" is a joke anyway.

  • source
  • hideshow 6 child comments
  • [–] 27 points 1 year ago (3 children)

    I mean, Secure Boot does actually help defend against evil maid attacks if paired with FDE. Someone can't just fuck with your /boot (CVE-2016-4484 nonwithstanding) to do naughty things with your system if you have Secure Boot enabled. Does that fit with most people's threat model? I dunno, probably not. It does actually do something useful though.

    My work computer has it enabled and I feel better for it. The issue described in the article is easily dealt with if you just keep up with your firmware updates using fwupd.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 18 points 1 year ago

    The actual problem is (and has been for a long time) the enormous amount of absolute trash-level uefi implementations.

    Updating keys is easy. Alas... a lot of them are completely broken beyond repair and fail everything but running with the pre-installed keys, which includes updating (or adding new) keys (bonus points for the really screwed up devices that even sign some their own hardware with the pre-installed MS keys thus bricking themselves if those keys are changed).

  • source
  • [–] 3 points 1 year ago (1 child)
  • [–] 1 point 1 year ago (1 child)

    If you use linux and are dependant on M$, youre doing it wrong

  • source
  • hideshow 2 child comments