logoalt Hacker News

romanivtoday at 4:47 PM2 repliesview on HN

I still hope that one of these days people in general will realize that executable signing and SecureBoot are specifically designed for controlling what a normal person can run, rather than for anything resembling real security. The premises of either of those "mitigations" make absolutely no sense for personal computers.


Replies

astrobe_today at 4:54 PM

I don't know about executable signing, but in the embedded world SecureBoot is also used to serve the customer; id est provide guarantees to the customer that the firmware of the device they receive has not been tampered with at some point in the supply chain.

show 6 replies
pjmlptoday at 5:26 PM

If only people didn't install Ask Jeeves toolbars all over the place and then asked their grandson during vacations to clean their computer.

show 1 reply