From: Greg KH <gregkh@gentoo.org>
To: "Michał Górny" <mgorny@gentoo.org>
Cc: gentoo-dev@lists.gentoo.org, gregkh@gentoo.org, lists@binarywings.net
Subject: Re: [gentoo-dev] Re: UEFI secure boot and Gentoo
Date: Sun, 17 Jun 2012 10:56:42 -0700 [thread overview]
Message-ID: <20120617175642.GB3721@kroah.com> (raw)
In-Reply-To: <20120617190616.186bd49a@pomiocik.lan>
On Sun, Jun 17, 2012 at 07:06:16PM +0200, Michał Górny wrote:
> On Sun, 17 Jun 2012 09:55:35 -0700
> Greg KH <gregkh@gentoo.org> wrote:
>
> > On Sun, Jun 17, 2012 at 05:51:04PM +0200, Michał Górny wrote:
> > > 2. What happens if, say, your bootloader is compromised?
> >
> > And how would this happen? Your bootloader would not run.
>
> Yes. I'm asking what happens next. Is there an easy way to replace it?
I do not know, you need to test this on a UEFI secure boot system to see
what happens.
> Or is your computer bricked until you run some other bootloader to
> replace the compromised one?
Probably.
> > > 3. What happens if the machine signing the blobs is compromised?
> >
> > So, who's watching the watchers, right? Come on, this is getting
> > looney.
>
> I'm just pointing out that this simply relies on trusting people. Much
> like not having those signatures.
Of course, this is life, and should not be anything "new" to you or
anyone else.
And before you get upset, do you trust the "people" who implemented the
firmware in your processor and I/O controllers? This argument is not
one that is worth discussing.
greg k-h
next prev parent reply other threads:[~2012-06-17 17:58 UTC|newest]
Thread overview: 76+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-06-15 4:28 [gentoo-dev] UEFI secure boot and Gentoo Greg KH
2012-06-15 4:45 ` Arun Raghavan
2012-06-15 4:56 ` Greg KH
2012-06-15 5:24 ` Arun Raghavan
2012-06-15 21:28 ` Matthew Thode
2012-06-15 5:48 ` Eray Aslan
2012-06-15 7:26 ` Michał Górny
2012-06-15 7:49 ` Florian Philipp
2012-06-15 8:06 ` Richard Farina
2012-06-15 8:24 ` Florian Philipp
2012-06-15 23:59 ` Greg KH
2012-06-16 8:33 ` Florian Philipp
2012-06-16 0:03 ` gregkh
2012-06-15 5:00 ` [gentoo-dev] " Duncan
2012-06-15 5:03 ` [gentoo-dev] " Ben de Groot
2012-06-15 5:08 ` Matthew Finkel
2012-06-15 5:24 ` Arun Raghavan
2012-06-15 7:12 ` Ben de Groot
2012-06-15 7:58 ` Richard Farina
2012-06-15 8:37 ` Florian Philipp
2012-06-15 11:32 ` Walter Dnes
2012-06-15 12:01 ` Rich Freeman
2012-06-15 12:48 ` Florian Philipp
2012-06-16 9:22 ` Maxim Kammerer
2012-06-17 17:03 ` Greg KH
2012-06-17 19:22 ` Maxim Kammerer
2012-06-15 10:50 ` Ben de Groot
2012-06-16 0:02 ` Greg KH
2012-06-15 4:45 ` Greg KH
2012-06-15 5:48 ` Philip Webb
2012-06-16 0:01 ` Greg KH
2012-06-16 3:18 ` Philip Webb
2012-06-15 21:35 ` Matthew Thode
2012-06-16 0:00 ` Greg KH
2012-06-15 4:50 ` [gentoo-dev] " Duncan
2012-06-15 5:01 ` Matthew Finkel
2012-06-15 7:54 ` Florian Philipp
2012-06-15 12:28 ` Walter Dnes
2012-06-15 12:55 ` Florian Philipp
2012-06-16 23:37 ` Steev Klimaszewski
2012-06-17 16:58 ` Greg KH
2012-06-17 17:24 ` Dale
2012-06-16 17:51 ` Michał Górny
2012-06-17 9:20 ` Florian Philipp
2012-06-17 15:51 ` Michał Górny
2012-06-17 16:55 ` Greg KH
2012-06-17 17:06 ` Michał Górny
2012-06-17 17:17 ` Rich Freeman
2012-06-17 17:28 ` Florian Philipp
2012-06-17 17:56 ` Greg KH [this message]
2012-06-17 16:56 ` Matthew Finkel
2012-06-17 17:10 ` Michał Górny
2012-06-17 17:40 ` Florian Philipp
2012-06-17 17:34 ` Sascha Cunz
2012-06-17 17:55 ` Rich Freeman
2012-06-17 18:00 ` Florian Philipp
2012-06-17 18:56 ` Sascha Cunz
2012-06-17 19:20 ` Graham Murray
2012-06-17 20:30 ` Florian Philipp
2012-06-17 23:07 ` Rich Freeman
2012-06-22 6:42 ` George Prowse
2012-06-15 4:57 ` [gentoo-dev] " Chí-Thanh Christopher Nguyễn
2012-06-15 12:18 ` Luca Barbato
2012-06-15 12:33 ` Rich Freeman
2012-06-15 23:56 ` Greg KH
2012-06-16 6:30 ` Michał Górny
2012-06-15 10:14 ` Rich Freeman
2012-06-15 11:26 ` Florian Philipp
2012-06-15 12:22 ` Luca Barbato
2012-06-15 12:45 ` Rich Freeman
2012-06-15 15:46 ` G.Wolfe Woodbury
2012-06-15 23:55 ` Greg KH
2012-06-16 0:41 ` Rich Freeman
2012-06-16 3:49 ` Greg KH
2012-06-16 23:52 ` Matthew Summers
2012-06-17 0:23 ` [gentoo-dev] " Duncan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20120617175642.GB3721@kroah.com \
--to=gregkh@gentoo.org \
--cc=gentoo-dev@lists.gentoo.org \
--cc=lists@binarywings.net \
--cc=mgorny@gentoo.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox