How Windows 10 Rewrites OS Architecture: Battle of SKM and IUM [pdf]
alex-ionescu.com
alex-ionescu.com
[1] Well, kind of. The Secure Boot configuration state is measured into PCR 7 on the TPM, so you can seal a secret to it and then have it fail if the Secure Boot configuration changes. But that's made difficult because updates to dbx (but not dbt) invalidate the state, so you need a lot of very careful handshaking in blacklist updates.
The problem I was trying to get to is that VSM allows itself to be activated without SB (which as you note, can also be done with malicious SB) and therefore there is no way to really 'trust' the VSM implementation.
Possible fixes to this would be to rely on SGX/TXT. But even that can be messed with -- but the attack surface is much harder than EDK-II.
Unless MS provide way to build and sign your copy of windows yourself. As with any other tech - the important thing is who holds the keys.
I may not agree with your whole post, bit this is key.
It's about control of your own hardware and it's gradually being taken away. One piece at a time.
Edit: also if something can be abused it is not a freedom but a granted temporary privilege.
Or the freedom to reset my device to a known-good state from read-only media so I know it's safe to use again after potentially being compromised through these slightly-too-clever new reprogrammable systems?
Your point seems to be about the chosen operating software's security model. I agree that flexibility here is woefully lacking in all the major desktop OSes today.
However, the original concern in this case seems to be about being able to choose the basic operating software for the system itself, which is an orthogonal issue to the one you're raising as I understand your comment.
Because the average Joe and Jane users don't understand anything about security, and prefer to loose freedom than having their computer exploited.
For mobile devices, or for devices like Chromebooks, you don't. It is only matter of time, until PCs change too, with apologies like 'nobody uses it anyway, why complicate things' etc. The frog must be boiled slowly, otherwise it backfires.
[1] The reasons for this design choice are understandable, even if I disagree with them
its not like they would ever break anti-trust...
Therefor your point is moot. It isn't your device, so you aren't throwing out anything you own.