Garrett: Secure Boot and Restricted Boot
Garrett: Secure Boot and Restricted Boot
Posted Mar 28, 2013 16:52 UTC (Thu) by ortalo (guest, #4654)Parent article: Garrett: Secure Boot and Restricted Boot
Personally I'd sum up as:
- UEFI as SecureBoot: neutral. You can buy. (If it's mine or you ask me I'll deactivate it. If you want to activate, either ask M$ or -preferably- that Matthew from Nebula on the web).
- whatever as RestrictedBoot: negative. Do not buy. (Or, that's your money.)
It seems to me this is in support of Matthew's position, though probably not as much as he would like.
But hey, I would also like him to work on fancier things like relying on a smartcard to check kernel or program signatures efficiently and things like that (and possibly on phones or portable devices). Nobody's willing to fund him for that? (After all, he seems especially competent and interested in that field.) The end result might be interesting enough to compete with proprietary restricted boot solutions based on its own technical and security merits (like most of free software). General market adoption is another issue (remember once upon time, Apple and M$ also tried to replace TCP/IP, but then they stopped). I also know of a few very specific niches where it may make a lot of sense any time (but niche markets are niches of course).
Funnily, all the (interesting) debate around UEFI has not made me change my position so much: support the man and forget about the thing... Admittedly, if he asks me to actively support the technology, this will make up for a short schizophrenic stasis. But I'll see.
