Microsoft Certificate Was Used To Sign Flame Malware
wiredmikey writes "Microsoft disclosed that 'unauthorized digital certificates derived from a Microsoft Certificate Authority' were used to sign components of the recently discovered Flame malware. 'We have discovered through our analysis that some components of the malware have been signed by certificates that allow software to appear as if it was produced by Microsoft,' Microsoft Security Response Center's Jonathan Ness wrote in a blog post. Microsoft is also warning that the same techniques could be leveraged by less sophisticated attackers to conduct more widespread attacks. In response to the discovery, Microsoft released a security advisory detailing steps that organizations should take in order block software signed by the unauthorized certificates, and also released an update to automatically protect customers. Also as part of its response effort, Microsoft said its Terminal Server Licensing Service no longer issues certificates that allow code to be signed."
And this is how they plan to monopolize Secure Boot (UEFI) and get rid of Linux? why should I trust that ONE KEY that microsoft plans to install on all motherboards?
JP
First they came for ARM on the desktop, and I didn't speak because I didn't care...
So much for "SafeBoot". maybe we shoulc now start calling it "unsafe boot"?
Free Martian Whores!
The same way they train home users to install another OS?
Boot from CD and hit 'Install'?
Nope. Not going to work in the Glorious People's Secure Boot Dictatorship.
In fact, I presume you won't even be able to boot from CD without disabling 'Secure Boot' in the BIOS.