I didn't say I didn't see a security issue (minor though it may be). I said that security is not the reason for this "fix" - the effort required for secure boot is completely out of balance with the potential exposure this plugs.
And if Microsoft is indeed pressuring vendors not to include an option to turn secure boot off, this is an ominous turn of events that would indeed force buyers to chooses carefully.
But as I said, I believe that those people who ask their tech buddies which computer to buy will be steered towards computers that give the option, or have no secure boot at all. This will ultimately force the vendors to discontinue models that lock down secure boot.
Yeah, you did: There is no "security exposure" that this plugs
> I said that security is not the reason for this "fix" - the effort required for secure boot is completely out of balance with the potential exposure this plugs.
The potential risk is massive. Malware that injects a hypervisor beneath the OS could be undetectable without external scanning and nearly unfixable for the typical user. Imagine botnets built like this. The OS is healthy, anti-malware says everything's great. Meanwhile the machine is being remotely controlled and no one knows it except the guy who's using it to hammer away as part of a DDoS attack, or using it to host child pornography, or whatever.
The effort required for secure boot actually seems quite small. The real effort is in making secure boot work for 3rd parties as well. That's a difficult problem because "I want to run some random crap in my bootloader" is in direct conflict with the "don't allow random crap to run in the bootloader" design goal.
> And if Microsoft is indeed pressuring vendors not to include an option to turn secure boot off, this is an ominous turn of events that would indeed force buyers to chooses carefully.
I seriously doubt that's happening.
> But as I said, I believe that those people who ask their tech buddies which computer to buy will be steered towards computers that give the option, or have no secure boot at all. This will ultimately force the vendors to discontinue models that lock down secure boot.
I agree. I think any vendor who sells a locked-down secure boot will see public backlash, and fix it in either future models or a firmware reflash.
And if Microsoft is indeed pressuring vendors not to include an option to turn secure boot off, this is an ominous turn of events that would indeed force buyers to chooses carefully.
But as I said, I believe that those people who ask their tech buddies which computer to buy will be steered towards computers that give the option, or have no secure boot at all. This will ultimately force the vendors to discontinue models that lock down secure boot.