←back to thread

658 points transpute | 1 comments | | HN request time: 0.255s | source
Show context
PrimeMcFly ◴[] No.35844325[source]
There is no reason to use a manufacture key anyway, at least for SecureBoot.

Obviously it isn't in everyone's skillset, but if you have the means there is nothing preventing you from generating and using your own key.

Honestly it seems like a good basic security precaution, not only to prevent against leaks like this, but also to counteract any backdoors (although kind of a moot point with chipmakers).

replies(3): >>35844568 #>>35844657 #>>35844906 #
Arnavion ◴[] No.35844657[source]
Secure Boot keys are unrelated to the leaked key in question. The Boot Guard key is used to verify the firmware itself that the CPU executes on boot. What the firmware happens to do afterwards, say it's a UEFI firmware that implements Secure Boot, is irrelevant to Boot Guard.
replies(1): >>35844833 #
1. PrimeMcFly ◴[] No.35844833[source]
Thank you for clarifying, realized that too late after commenting.