Comment by kachapopopow
4 hours ago
that defeats the point, having the "keys" allows malicious actors to perform the same kind of attacks... trust is protected by trusted companies...
certificate companies sell trust, not certificates.
4 hours ago
that defeats the point, having the "keys" allows malicious actors to perform the same kind of attacks... trust is protected by trusted companies...
certificate companies sell trust, not certificates.
Me managing my own (for example) secure boot keys does not inherently enable malicious actors. Obviously unauthorized access to the keys is an attack vector that whoever holds them needs to account for. Obviously it's not risk free. There's always the potential that a user could mismanage his keys.
There's absolutely no excuse for hardware vendors not to provide end users the choice.
> trust is protected by trusted companies...
The less control of and visibility into their product you have the less trustworthy they are.