Archive for June 6th, 2012

Red Hat’s UEFI Secure Boot Solution

RedHat intends to distribute/register signing keys for RedHat and Fedora boot-loaders. The plan seems to be to require one more hoop for distros to jump through to boot on future systems. The idea is that signed boot-loaders will increase security. I see an unholy mess, another layer of complexity in IT that is not really necessary for folks with physical security of their IT.

I work a lot with LTSP. Anything that makes it more difficult to boot a client machine is unwelcome. Is every OEM on the planet going to host thousands of signatures for every existing and future distro on the planet? No. This raises the barrier to entry for new distros, too. No longer will a new distro be able to boot on every hardware in existence. The idea that this kind of security will be “easy” is insane. If it were “easy” it would not be secure at all. Does anyone believe the malware artists won’t open their own key markets? Will keys that are compromised be recalled, killing many installations on a whim? Depending on M$ and its OEM-”partners” to facilitate the spread of FLOSS is madness.

“Some conspiracy theorists bristle at the thought of Red Hat and other Linux distributions using a Microsoft initiated key registration scheme. Suffice it to say that Red Hat would not have endorsed this model if we were not comfortable that it is a good-faith initiative.”

How soon they forget. Why trust compulsive serial bullies?

see Red Hat Clarifies Doubts Over UEFI Secure Boot Solution.

- Robert Pogson



Archives by Month

My Mission

My observations and opinions about IT are based on 40 years of use in science and technology and lately, in education. I like IT that is fast, cost-effective and reliable. I do not care whether my solution is the same as yours. I like to think for myself.

My first use of GNU/Linux in 2001 was so remarkably better than what I had been using, I feel it is important work to share GNU/Linux with the world. I have been blessed by working in schools where students and school systems have benefited by good, modular software easily installed in most systems.

I have shown GNU/Linux to thousands of students and hundreds of teachers over the years and will continue in some way doing that until I die in spite of the opposition.

Posts

    Writing

    3426 articles
    30503 comments

      Comments

      platforms
      linux 17408
      windows 12734
      macos 206
      sun 3
      wp 2

      browsers
      firefox 23843 
      safari 11832 
      chrome 11684 
      ie 4615 
      iceweasel 4236 
      opera 1641 
      konqueror 198 
      netnewswire 14 
      epiphany 2 
      flock 0 
      bonecho 0 
      lynx 0 

Bad Behavior has blocked 3505 access attempts in the last 7 days.