←back to thread

658 points transpute | 3 comments | | HN request time: 0.908s | source
Show context
discerning_ ◴[] No.35844121[source]
If these keys are leaked, they should be adopted by open source projects to disable secure boot.
replies(5): >>35844176 #>>35844425 #>>35844463 #>>35844475 #>>35844941 #
1. meepmorp ◴[] No.35844463[source]
But secure boot is a good thing! I want my machines to verify what they're loading at boot time!

I just want to specify the root of trust.

replies(1): >>35844621 #
2. yyyk ◴[] No.35844621[source]
There's mokutil to add your own key.
replies(1): >>35848255 #
3. csdvrx ◴[] No.35848255[source]
no, a mok is just adding an unprotected UEFI variable. It's not the same as adding your key which can say disallow running payloads signed by Microsoft key.