Elektrine lite

← Feed

@lispi314@udongein.xyz

Post #3187092

2024-07-25 20:04 UTC

@dangoodin@infosec.exchange @cstross@wandering.shop Will we finally start getting rid of platform keys and having users provision their own? That'd be nice. There's no reason to trust the corposcum not to sign malware for state surveillance agencies.

Replies (1)

  • @pinkforest@hachyderm.io 2024-07-25 20:41

    @lispi314@udongein.xyz @dangoodin@infosec.exchange @cstross@wandering.shop yus. He was right. 10y ago: > Users should be asked for permission ... “Not using keys,” he added. ... Keys will be compromised. Try to limit the damage .. let the user be in control.” > Per-host random keys.. even with the “stupid” UEFI checks disabled entirely if required. “They are almost certainly going to be *more* secure than depending on some crazy root of trust based on a big company, with key signing authorities that trust anybody with a credit card.”

    Open ##3187093