Which is not to say that this technology is useless, boot-level attacks are important to defend against even if they aren't common now. But one has to wonder whether the costs are worth the benefit, on end user machines?
Note that I'm not saying that Secure Boot is significant in the battle against bots, but rather that security is important even if there is not immediate benefits to the users of that particular machine.
Or do you mean mustache-twirling evil conspiracy "plausibly deniable" motives? I'm sure it's easy to ascribe malice to Microsoft's actions here.
I'm fairly flummoxed as to why this hasn't received antitrust review, frankly.
That's from the linked canonical article on the issue: http://blog.canonical.com/2011/10/28/white-paper-secure-boot...
It's also important to point out that the secure code chain is also held up (albeit often incorrectly) as an important criteria for a working DRM implementation. The content providers like that story, and like to hear about efforts to prevent rogue code from running. Certainly this has a lot to do with the Intel/Microsoft rush to secure boot.
The point still stands on whether or not this is actually the best or most effective way to go about tackling the problem. And as you point out the "unintended" of securing the DRM chain and of increasing vendor OS lock-in are not to be ignored and probably just as much a factor behind adoption as the purported security issues.
So verifying the bootloader with EUFI is a great thing that must happen. It could be completely transparent to most users -- their system works the same, it's just more secure. The problem is that Microsoft has engineered it so in practice only their key can be on the system to unlock it. Once this scheme gets established they might even be able to maintain a 'windows tax' just to unlock the hardware even if you don't even use their OS. That's really the only negative about EUFI.
But when you pressed Esc or F1 or whatever for a boot menu, instead of choosing what partition to boot from you choose which key. ie the list is
1) Microsoft, Inc. Operating System
2) Red Hat, Inc. Operating System
3) ...
So even if somebody hacked Red Hat and stole their key and signed something malicious, the user would still have to select that key on boot in order for it to run. Maybe the boot menu would only list keys that verified an actual installed OS.
In any case, just because you have a bunch of keys in the BIOS doesn't mean you have to automatically boot anything they sign.