Hacker News new | past | comments | ask | show | jobs | submit login

If you're flashing via the UEFI interface itself (which can have a very fancy terminal), the firmware might need to be signed. I bet Microsoft will not share the signing keys.



Production surface devices have intel bootguard enabled and the public key fused into the pch. You'd have to bypass it somehow.


That is only used to check firmware signatures, not UEFI binary signatures. You should be able to add keys to DB and KEK at your leisure. Also Microsoft has a paid program to sign UEFI binaries (that's why you can boot most Linux distributions on secure boot hardware).




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: