Secure Boot and Restricted Boot
mjg59.dreamwidth.org
mjg59.dreamwidth.org
"Yes, you were campaigning against Microsoft. However, when Apple implemented the Palladium spec to the letter, most people folded because they were more anti-Microsoft than pro-freedom and were taken by the shiny stuff. Now it is acceptable to the public to buy locked down devices."
Of course, this makes sense. Scape-goating doesn't require anyone to use their brains ;-)
Linux desktop users risk to go back to being a niche, just when they were starting to rise above it.
Good move, Microsoft.
PS: Oh, and you'd think the fact Secure Boot "CA" is controlled by an American company would raise some eye brows at Bruxelles ...
The CA is only controlled by an American company if you, the user, choose to stick with that CA. You are free to reconfigure your system to use a different CA.
The problem is that they don't specify any kind of common interface for doing so, or standard for key formats, or anything of the sort. So how it works can vary greatly between manufacturers, or may be buggy, or the like. So several prominent Linux distros have decided to ship bootloaders signed with Microsoft's keys, so that people can just install the distro without having to go through some hardware specific key loading process that may brick their machine.