Skip to content

Comment on Apple T2 Security Chip: Security Overview [pdf]parent

Comments

One interesting point in the discussion of UEFI secure boot: it appears there is no way to boot OSes other than Mac OS and Windows without disabling secure boot entirely.

Aren't there various linux bootloader shims signed by the MS key to workaround exactly this sort of regressive thinking ?

NOTE: There is currently no trust provided for the the Microsoft Corporation UEFI CA 2011, which would allow verification of code signed by Microsoft partners. This UEFI CA is commonly used to verify the authenticity of bootloaders for other operating systems such as Linux variants.

Thank god - you wouldn't want that enabled by default.

Some people might want secure boot with their own certs to work with Linux, but I don't see the gain in security if you are using a generic boot loader.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.