https://lwn.net/SubscriberLink/500231/0161d1d4b4b14c1a/

Really good summary that highlights the potential pitfalls of this situation.

One could simply ignore secure boot, requiring users to disable it before they can install Linux on their machines. That imposes a potentially scary or difficult task on those users; by the specification, secure boot cannot be disabled by the software directly. There may also be resistance from users who see a switch saying “turn off security” and don’t want to flip it. This approach will work fine for hard-core Linux users and developers, but seems certain to lose other kinds of users.

Pretty much hits the nail on the head there. If secureboot could be disabled through some admin control panel interface it would defeat the purpose since it’s basically meant to restrict rootkits that gain admin. So the user will either have to open the system up and flip a switch (not that daunting for the Chromebooks actually) or go through what is potentially a pain in the ass to get the keys working.



blog comments powered by Disqus

Published

13 June 2012

Categories

Tags