- Kongar@lemmy.dbzer0.comEnglish1 month
Unpopular opinion but I’m dying on this hill. Secure boot creates more problems than it solves.
- JiveTurkey@lemmy.worldEnglish1 month
I’d argue this is actually a popular opinion. IMO secureboot has just become a way for Microsoft to leverage it’s position and keep a strangle hold on industries they have no business being in.
The whole kernel level anti-cheat on win11 bullshit in the gaming industry is a good example. Essentially locking games to its platform and willing to sacrifice security to do so at our expense.
- 1 month
This is especially true on computers where it is impossible to change the signing keys. Smartphones, game consoles, many laptops, some desktops, smart TVs, IoT devices, modern cars, etc.
- CriticalMiss@lemmy.worldEnglish1 month
Arch Wiki had pointed out for years that Secure Boot is a flawed mechanism.
black0ut@pawb.socialEnglish
1 monthIt’s not flawed at all. But its purpose isn’t actually to secure anything. Its purpose is to complicate the installation of alternative OS and to perpetuate vendor lock in, while sounding like it’s “for your security”. In that regard, it has succeeded.
There is also TPM and Microsoft Pluton, which serve the same purpose.
A_norny_mousse@piefed.zipEnglish
1 month11 old and forgotten UEFI shim bootloaders at versions 0.9 and below that can be used to bypass UEFI Secure Boot on any UEFI-based machine that trusts Microsoft’s Microsoft Corporation UEFI CA 2011 third-party UEFI certificate authority (CA) certificate, regardless of the installed operating system (OS).
This “Trust” is one of my pet peeves. It’s $$$.
- naticus@lemmy.worldEnglish1 month
I get why you’d dislike that wording, but this is also how all certificate stores work, regardless of whether we’re talking Secure Boot, Windows or Linux. Gotta trust the top level as providing legitimate certificates to then trust everything underlying as coming from the correct parties.
Certificate are something I work with constantly at work and I fucking hate resolving issues with them lol.
- Victor@lemmy.worldEnglish1 month
IMO, broken ≠ vulnerable. Broken to me means it doesn’t work. There’s a difference, to me. 🤷♂️
sp3ctr4l@lemmy.dbzer0.comEnglish
1 monthSecure boot is supposed to be a lock.
Turns out there are 10 year old tricks that bypass that lock.
A lock that cannot deny access to people without proper key… is a bad lock.
sp3ctr4l@lemmy.dbzer0.comEnglish
1 monthNo.
Secure Boot is basically a ‘lock’, on the UEFI.
UEFI - Shim is basically a ‘lockpick’.
UEFI is the first step in your computer booting, turning on.
So, if Secure Boot is supposed to be a ‘lock’, that limits who can access the UEFI … but it turns out that there are many, old, UEFI - Shims, that defeat that ‘lock’… then Secure Boot is not a good ‘lock’.
I don’t mean to be rude but it seems like there might be a bit of language confusion going on here… In English, a ‘shim’ is a kind of crude/simple tool that can be used to break or bypass some actual physical locks.
So ‘UEFI-Shim’ basically means ‘a thing that breaks into your UEFI’.
- Victor@lemmy.worldEnglish1 month
I don’t think there’s a language barrier here. I’m fluent in English, and I know what a shim is, both IRL and in the software world. I’ve just not run into it in a boot loader context before. And I’m not really knowledgeable when it comes to secure boot, either. Just trying to understand. 🙂
Are you sure that’s a good phrasing though, “that breaks into your UEFI”?
A shim is usually something that you use to add or modify functionality by interception, right? Like a middle-ware, almost. So these old shims, are they responsible for functionality that directly has to do with Secure Boot, or something else?
If so, they are broken — i.e. not fulfilling their purpose.
If something else, they are not broken. They are just breaking something else, or making it vulnerable.
Am I making sense? Does it not make sense? Because after all, I don’t know much about the details of the subject matter. 😁





