|
|
|
|
|
by nickpsecurity
3727 days ago
|
|
"..but secure boot? What possible reason could you have for being against a system that prevents bootkits from pwning your machine?" The fact that I can do the same thing with firmware on a cheap ROM write-protected with a jumper. Additionally, the fact that there's competing I.P. in FOSS and corporate sectors for firmware that does trustworthy boot while leaving what's allowed in my control. "In general, code signing is a Good Thing, so long as the control remains in the hands of the user." With Microsoft and Intel style secure boot, it remains in the hands of Microsoft and Intel. And so on. Which is why we're against it. |
|
What is "Setup Mode"? It's "load your own root of trust and wipe any preinstalled keys". Nothing, nothing says that the root of trust has to be from Microsoft or Intel (and Secure Boot specification that is tested for Windows Logo certification would reject such system unless manufactured by Microsoft or Intel).
The difference with jumper is that you have standardized APIs etc. for the signing process, including a standardized "jumper".