Linked by Thom Holwerda on Fri 23rd Sep 2011 22:22 UTC, submitted by kragil
Permalink for comment 490677
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.
News
Linked by Thom Holwerda on 06/18/13 22:33 UTC
Linked by Anonymous on 06/18/13 22:26 UTC
Linked by Thom Holwerda on 06/18/13 22:25 UTC
Linked by Thom Holwerda on 06/18/13 17:45 UTC
Linked by Thom Holwerda on 06/18/13 17:32 UTC, submitted by poundsmack
Linked by Thom Holwerda on 06/17/13 17:58 UTC
Linked by Thom Holwerda on 06/17/13 17:52 UTC
Linked by Thom Holwerda on 06/14/13 21:03 UTC
Linked by Thom Holwerda on 06/14/13 20:46 UTC
Linked by Thom Holwerda on 06/14/13 17:32 UTC
More News »
Sponsored Links



Member since:
2009-05-30
Right Microsoft idea here is stuffed.
Issue one you have a 5 year old machine in the future MS has lost the key so you system can be attacked. Yet OEM has locked you motherboard and is providing no more update. So you cannot update bootloader to fix problem. So when microsoft pushes out update to bootloader signed with new key your computer now dies.
Who thinks this is a good idea now?
Great. Stupid moron move. The system needs a way to insert new keys and disable old ones. Other wise its a bit like saying when you lose your door keys you cannot replace your house locks.
If you cannot disable MS better insist on a way to replace the approval key. This does get around the Grub issue. Since the Linux distributors or end users could produce there own signing pair. Yes makes installation annoying. Ie fat formated usb key with a approval key to upload before able to install the OS.
Key of course is make the only way to upload the key inside bios software.
Linux way is better not having a default key set.