Post #4067860
2026-07-15 14:05 UTC
Problem being, of course, that you can add more certificates, but you can’t revoke the original M$ one. And since it’s vulnerable and you can’t get rid, then these exploits still work and there’s nothing you can do to stop it.
Replies (1)
-
@cmhe@lemmy.world 2026-07-17 05:49
On some systems you can clear all secure boot keys, including Microsoft’s, then provision your own and sign your bootloader or kernel with it. Windows cannot boot from such systems.