imo the only useful place to use secure boot is on a laptop with password protected bios and encrypted disk, in case someone wants to steal it they can’t recover your data or if they want to put a virus in your pc they literally can’t.
I don’t see any reason to put secure boot on a desktop PC that’s already locked inside your house.
That is not the purpose of Secure Boot. The purpose is to establish a chain of trust of all code running on the system from boot and as such eliminate rootkits that can hide from the OS. A classic example is the MBR bootkit. Of course that this is mostly out of the window if at some point in the chain the trusted code just runs untrusted code, like the bootloader or the OS running unsigned code. Also the implementation is terrible, a proper implementation would allow the user to use their own certificates and only their own certificates, otherwise a compromised generic certificate fucks everything up like it already happened.
disk encryption is much better with secure boot, because disk encryption requires a unencrypted partition, since the boot has to start somewhere unencrypted, and secure boot secures the unencrypted partition
They never said it did. Only that a laptop with encrypted drives is where secure boot makes sense. The OS can be as secure as it wants but if the drive isnt encrypted it can be accessed.
Secure boot is in case the OS gets tainted. It only allows a signed OS to boot.
For example when new nvidia drivers are autocompiled into my Tumbleweed kernel during an update, on reboot the srcureboot asks if I want to view the new key or allow it. I then have to enter a password to add the key…otherwise it won’t boot with that kernel.
Woo, Tumbleweed! Their support of it is a pretty strong plus. I would get that screen sometimes too but it confused me a lot and I ended up just being like “Accept key I guess? Oh cool it boots.”
What are you supposed to compare the key to? Nvidia’s repo on a website using a different device, or before you update or what? Is it like comparing checksums in Dolphin?
I’m not particularly afraid of Evil Maids vs. my Tumbleweed desktop, as I’m much too poor for hired help (lol), so I just turned it off.
They make compelling points about using it for laptops though.
Yeah Tumbleweed supports a lot of things. Whenever people have complained about Linux not doing something, I’m like “Uh, OpenSUSE does”
Since I’m updating the Kernel and nVidia driver modules, the system is making its own keypair, so I guess its not a check against a known supplied key but a machine specific key pair. Enrolling the key stores it to check against the kernel on boot.
I suppose it protects against Random malware installs changing files, or if somebody swaps a drive on you.
Maybe I am not informed enough, i don’t exactly know if i missed something , but i did what i would do under microslop, I reset to factory keys I enable secure boot in user mode and I boot.
When checking in the KDE security info, secure boot isn’t enabled.
I asked lenovo support on how to do it (along with how to do an bios update under Debian) and the just replied there is no support for Linux. For either of those for my model and disabled the option to get support from a real human for my serial number.
Maybe I would have needed to “enroll my keys”, I did not do that, mainly because I didn’t knew I needed to, and still dont know where to get my keys from and how to enroll them. Maybe you could enlighten me.
Side rant:
That I had to enter my full details including age and address and my serial number to even be able to get a support ticket is unbelievable imho
imo the only useful place to use secure boot is on a laptop with password protected bios and encrypted disk, in case someone wants to steal it they can’t recover your data or if they want to put a virus in your pc they literally can’t.
I don’t see any reason to put secure boot on a desktop PC that’s already locked inside your house.
That is not the purpose of Secure Boot. The purpose is to establish a chain of trust of all code running on the system from boot and as such eliminate rootkits that can hide from the OS. A classic example is the MBR bootkit. Of course that this is mostly out of the window if at some point in the chain the trusted code just runs untrusted code, like the bootloader or the OS running unsigned code. Also the implementation is terrible, a proper implementation would allow the user to use their own certificates and only their own certificates, otherwise a compromised generic certificate fucks everything up like it already happened.
You’re thinking bitlocker not secure boot
disk encryption is much better with secure boot, because disk encryption requires a unencrypted partition, since the boot has to start somewhere unencrypted, and secure boot secures the unencrypted partition
After looking into it, you are correct and I was mistaken. Thanks for correcting my misinformation.
Secured boot has nothing to do with encrypting your hard drive.
They never said it did. Only that a laptop with encrypted drives is where secure boot makes sense. The OS can be as secure as it wants but if the drive isnt encrypted it can be accessed.
Secure boot is in case the OS gets tainted. It only allows a signed OS to boot.
For example when new nvidia drivers are autocompiled into my Tumbleweed kernel during an update, on reboot the srcureboot asks if I want to view the new key or allow it. I then have to enter a password to add the key…otherwise it won’t boot with that kernel.
Woo, Tumbleweed! Their support of it is a pretty strong plus. I would get that screen sometimes too but it confused me a lot and I ended up just being like “Accept key I guess? Oh cool it boots.”
What are you supposed to compare the key to? Nvidia’s repo on a website using a different device, or before you update or what? Is it like comparing checksums in Dolphin?
I’m not particularly afraid of Evil Maids vs. my Tumbleweed desktop, as I’m much too poor for hired help (lol), so I just turned it off.
They make compelling points about using it for laptops though.
Yeah Tumbleweed supports a lot of things. Whenever people have complained about Linux not doing something, I’m like “Uh, OpenSUSE does”
Since I’m updating the Kernel and nVidia driver modules, the system is making its own keypair, so I guess its not a check against a known supplied key but a machine specific key pair. Enrolling the key stores it to check against the kernel on boot.
I suppose it protects against Random malware installs changing files, or if somebody swaps a drive on you.
That’s exactly mz setup, as I need to leave my work laptop unauthorized in a shared space for prolonged periods.
Can’t set up secure boot though because even fckin lenovo doesn’t provide the needed bios options for Linux nowadays -.-
Which bios options do you need for that? Not enough to enter secure boot setup mode (restore factory keys) and enroll your keys?
Maybe I am not informed enough, i don’t exactly know if i missed something , but i did what i would do under microslop, I reset to factory keys I enable secure boot in user mode and I boot.
When checking in the KDE security info, secure boot isn’t enabled.
I asked lenovo support on how to do it (along with how to do an bios update under Debian) and the just replied there is no support for Linux. For either of those for my model and disabled the option to get support from a real human for my serial number.
Maybe I would have needed to “enroll my keys”, I did not do that, mainly because I didn’t knew I needed to, and still dont know where to get my keys from and how to enroll them. Maybe you could enlighten me.
Side rant: That I had to enter my full details including age and address and my serial number to even be able to get a support ticket is unbelievable imho
My device isn’t included in the fwupd.
Okay, apparently Debian uses
shimwhich is signed by Microsoft. That means you do not need to enroll custom keys.I am using secure boot on a laptop with password-protected UEFI and disk encryption.
What’s the password?
hunter2
How do you know my cats name and favourite number
We actually don’t… We just see ******* only you can see it says hunter2
Do you not recognize me? I am your cat.
To play Valorant, why else
To play battlefield