Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Call me childish, but I don’t want to ask Microsoft to sign a certificate for me before I install software onto my own hardware.

I don’t care if it’s required for every installation of if it’s once per hardware. I want to install software without asking a third party for permission. I want this to be doable entirely offline.

Plus, keeping Microsoft’s CA installed greatest reduces any security which I’d get from SecureBoot.



> Plus, keeping Microsoft’s CA installed greatest reduces any security which I’d get from SecureBoot.

Can't you just remove all CAs from the UEFI and import only your own anyways with most mainboard vendors?


Yeah that's how my systems are set up. I also appreciate that each firmware let's me restore the original keys just in case without me having to manually back them up -- but they're not active for secure boot.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: