Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If every computer in the world is vulnerable to malware signed by a specific Microsoft key, how long do we think this key would remain secret? What will Microsoft do when (not if) that happens? Will they pay for the replacement of every PC and ARM device built to that point?

The benefit of breaking it and immediately gaining permanent undetectable access to every Windows-capable computer on the planet can offset a lot of cost.



If you want to make up stuff about Microsoft, at least make up something believable instead of straight up nonsense FUD.


With the correct signing keys, you could make every UEFI secure-boot-enabled machine in the world seamlessly run whatever you want them to. You could infect them with undetectable malware.

Now, imagine every computer on every office vulnerable to your malware because you have the signing keys used by Microsoft.

How much computing power would you dedicate to get that keys? How much money would you spend? A billion? Ten? That's the price of a single fully-loaded bomber these days. How can you be absolutely sure the keys are kept secure enough from someone willing to spend a fraction of their military budget to get what could amount to be the ultimate cyberweapon?


>With the correct signing keys, you could make every UEFI secure-boot-enabled machine in the world seamlessly run whatever you want them to. You could infect them with undetectable malware. >Now, imagine every computer on every office vulnerable to your malware because you have the signing keys used by Microsoft.

Even if that doomsday scenario comes into play, things would just go back to... the present.. where there is no locked bootloader.

So I really fail to understand your hype.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: