[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20121103005504.50236879@pyramind.ukuu.org.uk>
Date: Sat, 3 Nov 2012 00:55:04 +0000
From: Alan Cox <alan@...rguk.ukuu.org.uk>
To: Matthew Garrett <mjg@...hat.com>
Cc: Chris Friesen <chris.friesen@...band.com>,
"Eric W. Biederman" <ebiederm@...ssion.com>,
James Bottomley <James.Bottomley@...senPartnership.com>,
Eric Paris <eparis@...isplace.org>,
Jiri Kosina <jkosina@...e.cz>, Oliver Neukum <oneukum@...e.de>,
Josh Boyer <jwboyer@...il.com>, linux-kernel@...r.kernel.org,
linux-security-module@...r.kernel.org, linux-efi@...r.kernel.org
Subject: Re: [RFC] Second attempt at kernel secure boot support
On Sat, 3 Nov 2012 00:23:39 +0000
Matthew Garrett <mjg@...hat.com> wrote:
> On Fri, Nov 02, 2012 at 11:46:07PM +0000, Alan Cox wrote:
> > On Fri, 02 Nov 2012 16:19:39 -0600
> > Chris Friesen <chris.friesen@...band.com> wrote:
> > > On 11/02/2012 04:03 PM, Eric W. Biederman wrote:
> > > > Matthew Garrett<mjg59@...f.ucam.org> writes:
> > > >> And if any of them are used to attack Linux, we'd expect those versions
> > > >> of Windows to be blacklisted.
> >
> > This is the first laugh. So they revoke the key. For that to be useful
> > they must propogate that into all the boxes in warehouses and all the new
> > boxes. If they do that then all the existing store stock of Windows 8 DVD
> > and CD media needs replacing.
>
> Revocation is done via Windows Update. If they refuse to do that, well,
> lawyers, right?
Doesn't work. Microsoft themselves have been bouncing up and down in the
press about malware installed in the supply chain. They have to revoke
the key in new systems as supplied. That means they can't install the
Windows 8 DVD which means they can't access windows update which means
all the media has to be updated.
It also means all customers with rescue media and restore media would
lose the ability to restore that media so those would need reissuing or a
mechanism to replace them.
Can't really see it happening.
As any crypto systems and economics people will tell you key revocation
is hard and the digital bits of it while hard are usually the tip of the
iceberg.
Alan
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Powered by blists - more mailing lists