Someone wrote in [personal profile] mjg59 2011-10-24 04:40 pm (UTC)

Rather Upside Down Reasoning

Secure boot doesn't give you control of your machine. It gives the person who creates the signatures control. Unless you have the power to create and trust your own signatures, you don't have control.

This doesn't stop tampering from going on. It just stops your machine from running after it's been tampered with. In theory, this gives you the opportunity to reverse the tampering. In practice, we'll see.

I don't generally trust firmware/hardware based encryption. Without the ability for the user to modify the key database himself it takes away more control of the machine, and in no way is it guaranteed to be unhackable (though it may afterward be unfixable). Give the user the ability to control the key database, and then I might trust it a bit more.

Post a comment in response:

If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org