Poettering: Brave new trusted boot world
Poettering: Brave new trusted boot world
Posted Nov 2, 2022 17:44 UTC (Wed) by luto (subscriber, #39314)In reply to: Poettering: Brave new trusted boot world by farnz
Parent article: Poettering: Brave new trusted boot world
With a standard Secure Boot configuration, can't an attacker simply boot any signed (via Microsoft keys or anything transitively signed or approved) OS that doesn't use PCR 11?
In general, the entire Secure Boot ecosystem seems to be set up for one of three use cases:
1. Only Windows. Useless here.
2. Only Windows, something that Microsoft considers benign, or whatever a physically present user wants to run. Fine as long as the attacker isn't a physically present user for this purpose and nothing that Microsoft considers benign leaves PCR 11 set to zero.
3. Custom configuration. Fine.
