• addie@feddit.uk
    link
    fedilink
    English
    arrow-up
    7
    ·
    2 个月前

    Problem being, of course, that you can add more certificates, but you can’t revoke the original M$ one. And since it’s vulnerable and you can’t get rid, then these exploits still work and there’s nothing you can do to stop it.

    • Default Username@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      12
      ·
      edit-2
      2 个月前

      Computers shouldn’t come with Microsoft keys preinstalled to begin with (or an operating system for that matter). Microsoft being able to have Windows preinstalled on the vast majority of non-Apple PCs is how they gained their monopoly in the first place.

    • orclev@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 个月前

      You should be able to remove any or all the certs as well, although I could see an argument for requiring you to enter the BIOS to do that.

    • cmhe@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 个月前

      On some systems you can clear all secure boot keys, including Microsoft’s, then provision your own and sign your bootloader or kernel with it. Windows cannot boot from such systems.