still a few glitches in the system...
still a few glitches in the system...
Posted Nov 20, 2012 15:34 UTC (Tue) by davidescott (guest, #58580)In reply to: still a few glitches in the system... by mjw
Parent article: Bottomley: Adventures in Microsoft UEFI Signing
YTF is this process automated? Is Microsoft anticipating such a great need for custom bootloader's that they can't just have someone check a email mailbox? Who is going to want to have their own signed bootloaders and be willing to pay the fee to get one... A half-dozen linux distributors, a few dozen government agencies, X many development teams of major corporations. Everyone else is just going to disable secure boot. Unless X is really large this seems like a relatively minor part-time task for a single developer.
Putting the whole process on some website just opens you up to attacks on that website. An enterprising cracker might find a way to inject code into the signing program website and freely generate as many shims with new keys as he wants and permanently topple the house of cards that is secure boot.
The cynic in me says MSFT recognizes that there is money to be made in selling secure boot keys to malware authors and then revoking them a month later, and they want to automate the process so they can maximize the revenue stream.
