Hacker News new | ask | show | jobs
by ACCount37 18 days ago
Would it?

A bootkit doesn't give you any more access - only more persistence. At the price of having to tailor a payload to a hardware and software platform very carefully. For most attackers, that's just not worth it.

Now, if what you want to "secure" is your ability to gatekeep what software users can and can't install? What sources they can and can't consume media from? What system-level spyware and adware users can and can't remove? What operators users can and can't connect to? Then, suddenly, "secure boot" makes an awful lot of sense.

Which is exactly how "secure boot" is treated by vendors nowadays. It's there to "secure" something alright. It's there to chain device software to the device vendor securely.

There's a reason why modern "secure boot" originated on gaming consoles and TV boxes.

1 comments

> There's a reason why modern "secure boot" originated on gaming consoles and TV boxes.

Yes, because hardware is sold at or below cost, and giving away a general purpose computer without reaping the long term upside is a recipe for disaster.

But look at the prevalence of cheating on PC games versus console and tell me secure boot does nothing for actual security.

> cheating

> security

How are these two connected? Are you talking about security of companies from the users?

Yes? And users from each other?

If you’re so far into the “I buy it, nobody can tell me what to do with it” camp that you think it’s unethical for companies to try to stop cheating in multiplayer games… well, we don’t have much in common.

You approach basically makes general-purpose computers/phones impossible in order to save multiplayer games.
If phones didn't have secure boot nowadays inevitably little Johnny would (unknowingly) install a rootkit on his mom's phone for the promise of free vbucks or some see through walls app.
This is just FUD designed to remove the ownership of our devices.