Reworking kexec for signatures
Reworking kexec for signatures
Posted Jun 27, 2014 17:01 UTC (Fri) by paulj (subscriber, #341)In reply to: Reworking kexec for signatures by raven667
Parent article: Reworking kexec for signatures
True, at present users can still add their own keys to *some* UEFI key databases or disable SecureBoot on *some* UEFI systems (some UEFI systems do not allow one or both, either by design (e.g. ARM) or by bug/accident).
How long local users will still be allowed to subvert Windows SecureBoot on UEFI PCs, we shall see. I hope I'm proven to be an unnecessarily alarmist skeptic, however the number of systems afflicted by DRM/locked-down-computing seems to keep steadily increasing over the decades, rather than decreasing.
