I dont like secure boot on Linux anyway.
linuxmemes
Hint: :q!
Sister communities:
Community rules (click to expand)
1. Follow the site-wide rules
- Instance-wide TOS: https://legal.lemmy.world/tos/
- Lemmy code of conduct: https://join-lemmy.org/docs/code_of_conduct.html
2. Be civil
- Understand the difference between a joke and an insult.
- Do not harrass or attack users for any reason. This includes using blanket terms, like "every user of thing".
- Don't get baited into back-and-forth insults. We are not animals.
- Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
- Bigotry of any kind will not be tolerated. This is an LGBTQ+-friendly community -- if that is a problem for you, you should leave.
3. Post Linux-related content
- Including Unix and BSD.
- Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of
sudoin Windows. - No porn, no politics, no trolling or ragebaiting.
- Don't come looking for advice, this is not the right community.
4. No recent reposts
- Everybody uses Arch btw, can't quit Vim, <loves / tolerates / hates> systemd, and wants to interject for a moment. You can stop now.
5. π¬π§ Language/ΡΠ·ΡΠΊ/Sprache
- This is primarily an English-speaking community. π¬π§π¦πΊπΊπΈ
- Comments written in other languages are allowed.
- The substance of a post should be comprehensible for people who only speak English.
- Titles and post bodies written in other languages will be allowed, but only as long as the above rule is observed.
6. (NEW!) Regarding public figures
We all have our opinions, and certain public figures can be divisive. Keep in mind that this is a community for memes and light-hearted fun, not for airing grievances or leveling accusations. - Keep discussions polite and free of disparagement.
- We are never in possession of all of the facts. Defamatory comments will not be tolerated.
- Discussions that get too heated will be locked and offending comments removed. Β
Please report posts and comments that break these rules!
Important: never execute code or follow advice that you don't understand or can't verify, especially here. The word of the day is credibility. This is a meme community -- even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don't remove France.
Nothing more secure than a computer that wonβt start up.
I agree, bricks have been known to get rid of problems.
imo the only useful place to use secure boot is on a laptop with password protected bios and encrypted disk, in case someone wants to steal it they can't recover your data or if they want to put a virus in your pc they literally can't.
I don't see any reason to put secure boot on a desktop PC that's already locked inside your house.
That is not the purpose of Secure Boot. The purpose is to establish a chain of trust of all code running on the system from boot and as such eliminate rootkits that can hide from the OS. A classic example is the MBR bootkit. Of course that this is mostly out of the window if at some point in the chain the trusted code just runs untrusted code, like the bootloader or the OS running unsigned code. Also the implementation is terrible, a proper implementation would allow the user to use their own certificates and only their own certificates, otherwise a compromised generic certificate fucks everything up like it already happened.
I need it for my Windows 11 install for a few games on there that require it.
Secure boot is in case the OS gets tainted. It only allows a signed OS to boot.
For example when new nvidia drivers are autocompiled into my Tumbleweed kernel during an update, on reboot the srcureboot asks if I want to view the new key or allow it. I then have to enter a password to add the key...otherwise it won't boot with that kernel.
Woo, Tumbleweed! Their support of it is a pretty strong plus. I would get that screen sometimes too but it confused me a lot and I ended up just being like "Accept key I guess? Oh cool it boots."
What are you supposed to compare the key to? Nvidia's repo on a website using a different device, or before you update or what? Is it like comparing checksums in Dolphin?
I'm not particularly afraid of Evil Maids vs. my Tumbleweed desktop, as I'm much too poor for hired help (lol), so I just turned it off.
They make compelling points about using it for laptops though.
Yeah Tumbleweed supports a lot of things. Whenever people have complained about Linux not doing something, I'm like "Uh, OpenSUSE does"
Since I'm updating the Kernel and nVidia driver modules, the system is making its own keypair, so I guess its not a check against a known supplied key but a machine specific key pair. Enrolling the key stores it to check against the kernel on boot.
I suppose it protects against Random malware installs changing files, or if somebody swaps a drive on you.
Right? OpenSUSE stopped my distrohopping way before I thought I would. I love it.
Ahhh thank you, that makes a lot more sense! I don't feel too at-risk on my desktop, but if I ever find myself having to take a laptop to like, DEF-CON, then sounds like it'd be pretty essential, along with full-disk-encryption, AppArmor/SElinux, and all those other "wildly inconvenient but more secure" protocols set up.π (Lmao that would be terrifying.)
I might try to re-enable it just for the experience. After all, never know when some insane automated malware will hit the 'net that somehow exploits boot like that, and freaks out everyone who said "Nahh that's not possible."
Everything about secure boot is a mistake.
I would disagree. The idea is great; eliminate preboot malware by trusting the whole boot stack. It has a place in computing and I would like to see it be something easier to work with.
Pretty much everything about how it's currently implemented is a mistake, I'll agree with.
More like who is implementing it. Take MS out of the picture and set it as an open standard.
It is open, oddly enough. It's just that nobody ships anything other than Microsoft's keys. You can add your own. It's just that it is a tedious, manual process.
Depends on the distro! I could do it in 5 minutes with my bazzite installation: https://docs.bazzite.gg/General/Installation_Guide/secure_boot/
Very happy surprise when setting up my new PC :)
Microsoft has unofficial support for ext4 for their EFI partitions on their azure cloud, which in itself is a violation of their standard.
UEFI doesn't forbid you from implementing additional file systems, it just requires everyone to support UEFI-FAT. iBoot for example supports booting from HFS volumes.
And who has that implementation?
iBoot is the bootloader on all Apple products.
But who else can use that?
You are free to implement any filesystem driver, and either load it in your custom implementation of EFI, or from an EFI image stored on a FAT partition. The EfiFs project provides many drivers under a GPL, including exFAT, Btrfs, ext2-4, NTFS, ISO9660 (cdfs), ZFS and also HFS(+).
Ooh thanks I need to explore this thing!
if only secureboot support hibernate
My secure boot with hibernate works perfectly fine, or rather it did work fine before hibernate started freezing my system, secure boot or not.
With Linux? Kernel signed with your own key to get out of lockdown mode restrictions?
There are no lockdown mode restrictions on my system. Kernel is not signed, but i switched to UKIs a couple months ago (hibernation worked fine with these).
It is worth noting that the failure is hibernating, not resuming. Normally hibernate takes ~1 minute with fans spinning at max speed, but it recently started not finishing and instead being stuck on a black screen for more than 30 minutes without the fans running until i run out of patience (i hibernate before i go to sleep or head out) and force power off the system (power button 10 second press on my system).
Oof, I tried alpine for a bit, nothing worked. That was just beyond me for little gain.
Alpine is dead simple if used for whatβs itβs good at. The LBU is its best feature. Itβs great on shitty ARM boards that digest SD cards. I use it on NUT servers throughout my network.
That is not my use case, I don't know any of those words !
Now I'm curious. What did you try that didn't work?
It was on an 08/ish laptop I wanted to just use for simple dvd watching and such. Had a lot of sound and disc issues. I'm a noob tho so went back to mint.
Same here, I run Mint everywhere I can, and the XFCE edition works especially well in old machines.
Alpine is better suited for servers and especially containers, because the images can be really small. If you got enough RAM, there's an installation mode that runs on it without writing to disk, pretty cool for systems where you want always to reboot in the same state.
Yea I wouldn't choose a musl/BusyBox distro for my daily driver.
sbctl is a nice tool for setting up secure boot:
https://github.com/Foxboron/sbctl
Yes works well for me.