Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Imagine then a backdoor that allows a third party to remove Microsoft's key from UEFI.

All of a sudden, no Windows box is bootable.



The problem is that the UEFI would not be writable (at least if you aren't lucky), so you can neither remove MS key nor add your own.

If it would, of course malware would install its key and remove MS one to make machine only bootable with their payload.


>Imagine then a backdoor that allows a third party to remove Microsoft's key from UEFI.

You seem to have no clue how UEFI works. The keys are not stored in some magical place in the cloud. Removing MS's key from UEFI(even if it were possible) will only make Windows on that machine unbootable.


I was going with guard-of-terra's idea that all Chinese-made machines would be required to come with a key that could then be used in whatever cyberattack (or even spy-your-citizens-ware) the Chinese government wants to employ.

In this case, the Chinese won't even need to do the cyberattack themselves. Just leaking one of the signing keys to a willing third party would be bad enough.

Since a system that doesn't allow the removal of a compromised key is useless, there would be a way to remove Microsoft's key from all successfully compromised machines, rendering them useless.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: