this post was submitted on 07 Oct 2024
367 points (96.5% liked)

Technology

58599 readers
4214 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 4 points 4 days ago (2 children)

It's not for you, it's for them. Secure boot means it only runs their operating system, not yours. Trusted enclave means it secures their DRM-ware from tampering by the user who owns the PC.

[–] [email protected] 15 points 4 days ago (1 children)

Secure boot means that only the intended bootloader runs, it can be any one, but it just needs to be the intended one.

Secure boot works with Linux.

[–] [email protected] 1 points 4 days ago (1 children)

It works for now on x86-64, yes. For now. As always, we are one "think of the children" crisis away from lobbyists taking that option away.

[–] [email protected] 9 points 4 days ago (1 children)

What? I think you maybe just don't know what purpose secure boot serves.

It's not a tool to vendor lock computers, it's a tool to establish a chain of trust to protect the boot process by only allowing cryptographically signed images from executing. Anyone can sign things for secure boot by simply creating an x509 certificate and importing it. If vendors wanted to prevent you from running a different operating system, they would just lock it down completely as is done in many devices like mobile phones and proprietary electronics.

[–] [email protected] 3 points 4 days ago

^ this People are very ignorant about what secure boot actually is.

[–] [email protected] 4 points 4 days ago

What do you mean? I remove all vendor keys and enroll my own secure boot keys. This way only my install with my bootloader signed by my keys will boot.