Live data from Hacker News

Linux and Secure Boot certificate expiration

lwn.net

271–272 of 272 posts

Re: Linux and Secure Boot certificate expiration

#271
post #223

It's not just secure boot. Modern OS have certificates all over the place. These are ticking self-destruct time bombs in those machines that the manufacturers of hardware based on these OS may not necessarily realize. I am thinking ATM machines, voting machines, medical equipment, smart-fridges and other IOT, probably many cars, etc.

Oh, they realize it just fine. To them it is just another source of revenue. Planned obsolescence is going to wipe out our digital heritage at some point.

> Planned obsolescence is going to wipe out our digital heritage at some point.

I presume words like "Crowdstrike" or "Microsoft Update" don't say anything to you. /s

Re: Linux and Secure Boot certificate expiration

#272

Earlier quoted context omitted.

Take an iPhone or a Switch. Then disable Secure Boot on it. Good fucking luck. The reason why Apple or Nintendo go out of their way to make this impossible isn't user security. It's the "security" of their 30% App Store cut. Out in the wild, Secure Boot exists to "secure" vendor revenue streams - and PCs are the only devices where it's even possible for the user to disable it. Most of the time. What's happening in sm…

> It's the "security" of their 30% App Store cut. > most PC manufacturers don't have their own app store. I feel like you misunderstand what Secure Boot does. It has absolutely nothing to do with userspace apps or app sideloading. It's true that you can't easily sideload apps on Apple devices - but that has absolutely nothing to do with Secure Boot, neither do userspace apps have anything to do with it on any other d…

Secure boot is what stops you from putting an OS on there that doesn’t have those restrictions
Post reply on HN