Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Because almost no vendor wants to give you the keys to your system voluntarily. If secure boot puts the users in charge, I'm all for it. But there are forces at work to subvert the system to achieve a better vendor lock-in. And providing them with better means to that end is unethical.


I've never been on a system where I couldn't swap the keys in UEFI. Does mokutil not work on your system?


You know that this feature only works because Microsoft added it to the requirements of the Windows Logo program for x86 based computers almost at the last minute. Mainboard manufacturers would otherwise cut corners and add the MS signing key as the only unchangeable key to the system.

At the same time, MS specified for ARM computers that want to run Windows that the key must be fixed and irreplaceable.


Go into the BIOS and set your own keys.


I can do that now. But who guarantees that my next mainboard still has that feature?


Shim allows you to branch to an arbitrary additional root of trust




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: