• RiQuY@lemmy.zip
    link
    fedilink
    arrow-up
    0
    ·
    22 hours ago

    imo the only useful place to use secure boot is on a laptop with password protected bios and encrypted disk, in case someone wants to steal it they can’t recover your data or if they want to put a virus in your pc they literally can’t.

    I don’t see any reason to put secure boot on a desktop PC that’s already locked inside your house.

      • hirihit640@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        0
        ·
        6 hours ago

        disk encryption is much better with secure boot, because disk encryption requires a unencrypted partition, since the boot has to start somewhere unencrypted, and secure boot secures the unencrypted partition

        • spacegoat@lemmy.world
          link
          fedilink
          arrow-up
          0
          ·
          6 hours ago

          After looking into it, you are correct and I was mistaken. Thanks for correcting my misinformation.

      • Auth@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        13 hours ago

        They never said it did. Only that a laptop with encrypted drives is where secure boot makes sense. The OS can be as secure as it wants but if the drive isnt encrypted it can be accessed.

    • BCsven@lemmy.ca
      link
      fedilink
      arrow-up
      0
      ·
      15 hours ago

      Secure boot is in case the OS gets tainted. It only allows a signed OS to boot.

      For example when new nvidia drivers are autocompiled into my Tumbleweed kernel during an update, on reboot the srcureboot asks if I want to view the new key or allow it. I then have to enter a password to add the key…otherwise it won’t boot with that kernel.

      • MonkeMischief@lemmy.today
        link
        fedilink
        arrow-up
        0
        ·
        9 hours ago

        Woo, Tumbleweed! Their support of it is a pretty strong plus. I would get that screen sometimes too but it confused me a lot and I ended up just being like “Accept key I guess? Oh cool it boots.”

        What are you supposed to compare the key to? Nvidia’s repo on a website using a different device, or before you update or what? Is it like comparing checksums in Dolphin?

        I’m not particularly afraid of Evil Maids vs. my Tumbleweed desktop, as I’m much too poor for hired help (lol), so I just turned it off.

        They make compelling points about using it for laptops though.

    • SomeLemmyUser@discuss.tchncs.de
      link
      fedilink
      arrow-up
      0
      ·
      19 hours ago

      That’s exactly mz setup, as I need to leave my work laptop unauthorized in a shared space for prolonged periods.

      Can’t set up secure boot though because even fckin lenovo doesn’t provide the needed bios options for Linux nowadays -.-

      • ChaosMonkey@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        0
        ·
        3 hours ago

        Which bios options do you need for that? Not enough to enter secure boot setup mode (restore factory keys) and enroll your keys?

  • Richard@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    23 hours ago

    Deciding to turn on secureboot on any distro that doesn’t support it out of the box is always a mistake.

    Still have nightmares from that one time i tried doing it under nixOS…

    • Billegh@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      1 day ago

      I would disagree. The idea is great; eliminate preboot malware by trusting the whole boot stack. It has a place in computing and I would like to see it be something easier to work with.

      Pretty much everything about how it’s currently implemented is a mistake, I’ll agree with.

        • Billegh@lemmy.world
          link
          fedilink
          arrow-up
          0
          ·
          6 hours ago

          It is open, oddly enough. It’s just that nobody ships anything other than Microsoft’s keys. You can add your own. It’s just that it is a tedious, manual process.

      • slacktoid@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        24 hours ago

        Microsoft has unofficial support for ext4 for their EFI partitions on their azure cloud, which in itself is a violation of their standard.

        • libewa@feddit.org
          link
          fedilink
          arrow-up
          0
          ·
          23 hours ago

          UEFI doesn’t forbid you from implementing additional file systems, it just requires everyone to support UEFI-FAT. iBoot for example supports booting from HFS volumes.