255
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
(www.welivesecurity.com)
This is a most excellent place for technology news and articles.
What problem does it create? Its a good tech and we absolutely should be cryptographically verifying the boot process to ensure it hasnt been tampered with.
Because it's proprietary and in 99% of cases actually means "Windows Boot", and isn't very compatible with other OS. Windows is basically in charge of the entire technology and doesn't have a history of being friendly to other OS.
For a while Linux was completely blocked by this setting, which was yet another technical barrier to getting into Linux because you had to fuck around in your scary UEFI settings otherwise your PC would be soft-bricked after installing Linux. Nowadays it's slightly supported by some distributions but Microsoft could of course change it at any time.
Further reading: https://wiki.ubuntu.com/UEFI/SecureBoot
The way it should work is that during the OS install the OS can ask to have a cert added to the keystore at which point UEFI pops up a screen that says something like:
This would at least be a vendor agnostic way of enrolling certificates instead of the MS certificate just always being pre-installed. It should also of course be publicly documented exactly how the process works so everyone can use it.
Universal Blue distros do that. For some reason you need to enter a password though.
This is the MOK (Machine Owner Key), which is part of the shim bootloader, not UEFI secure boot.
The shim bootloader is signed by Microsoft UEFI secure boot keys, so Microsoft is the root of trust there.
On some systems you can delete all Secure Boot keys, and provision your own, then you don't need the shim bootloader and can sign your own bootloader or Linux kernel directly. Windows would not be able to boot on those systems.