On Thu, Feb 28, 2013 at 09:43:10AM -0600, Chris Friesen wrote: > On 02/28/2013 01:57 AM, Florian Weimer wrote: > > >In any case, there's another reading of the UEFI Secure Boot > >requirements: you may run any code you wish after calling > >ExitBootServices(). That could be an unsigned, traditional GRUB. But > >this will not generally address the issue of dual-booting Windows 8 in > >such a way that Windows sees that the device has enabled Microsoft > >Secure Boot. > > Would it be possible to have a signed bootloader that allows booting > Win8 from within the secure environment, or it could exit the secure > environment and run unsigned grub?
What would stop the unsigned grub from installing a firmware hook that lies about whether or not Secure Boot is enabled, and then booting Windows? -- Matthew Garrett | mj...@srcf.ucam.org -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majord...@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/