Path: csiph.com!v102.xanadu-bbs.net!xanadu-bbs.net!feeder.erje.net!us.feeder.erje.net!bloom-beacon.mit.edu!bloom-beacon.mit.edu!panix!not-for-mail From: ruben safir Newsgroups: comp.os.linux.misc,alt.os.linux.slackware,alt.os.linux.debian Subject: Re: Let's not bluff ourselves. Date: Sat, 13 Jun 2015 16:06:34 -0400 Organization: PANIX Public Access Internet and UNIX, NYC Lines: 18 Message-ID: References: NNTP-Posting-Host: www.mrbrklyn.com Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-Trace: reader1.panix.com 1434225994 12330 96.57.23.82 (13 Jun 2015 20:06:34 GMT) X-Complaints-To: abuse@panix.com NNTP-Posting-Date: Sat, 13 Jun 2015 20:06:34 +0000 (UTC) User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.7.0 In-Reply-To: Xref: csiph.com comp.os.linux.misc:14923 On 06/11/2015 10:32 PM, David W. Hodgins wrote: > On Thu, 11 Jun 2015 13:42:33 -0400, wrote: > >> we can't be free of the crushing heel of M$. > > Turn off secure boot, and don't buy a system where that cannot be done. > > Regards, Dave Hodgins > If you understand UEFI then you understand that on a service, this is not a secure thing to do. The capacity of UEFI and the boot shell is too powerful in order to run it without a signed binary. Its a crappy design, but that is how it is. UEFI is an entire unvetted and insecure OS that runs in bootspace. Ruben