UEFI bootkit

Heinz Diehl htd at fritha.org
Fri Sep 21 10:46:13 UTC 2012


On 21.09.2012, Eddie G. O'Connor Jr. wrote: 

> >Sorry for my maybe stupid question but why there must my Microsoft's key
> >on motherboard and not Fedora's one?

Because Microsoft dominates the hardware market, if you like it or
not.

>  Why Linux vendors don't intend to
> >install theirs keys to revers the situation so that Microsoft would have
> >to sign the keys? Or maybe keys from M$ and Fedora could coexist?

This has been discussed several times. In short: it's unlikely that
all hardware vendors will implement all the different keys from
different distributions. It's even quite unlikey that they will
implement even one key which fits all distributions. For further
information you could read Matthew Garretts blog.

> My thoughts EXACTLY! It would seem that the Open Source Community should
> have their OWN UEFI / key / signing process that eliminates Microsoft from
> the equation altogether! I for one would (and already DO!) donate and
> support different projects within the community and would LOVE to see
> something like this take off

A good idea. Now the only thing you have to do is  that you would have all the different
hardwar vendors motivated to ship their hardware with this key...

 


More information about the users mailing list