• RiQuY@lemmy.zip
    link
    fedilink
    arrow-up
    72
    arrow-down
    1
    ·
    2 days ago

    imo the only useful place to use secure boot is on a laptop with password protected bios and encrypted disk, in case someone wants to steal it they can’t recover your data or if they want to put a virus in your pc they literally can’t.

    I don’t see any reason to put secure boot on a desktop PC that’s already locked inside your house.

    • Coriza@lemmy.world
      link
      fedilink
      arrow-up
      10
      ·
      23 hours ago

      That is not the purpose of Secure Boot. The purpose is to establish a chain of trust of all code running on the system from boot and as such eliminate rootkits that can hide from the OS. A classic example is the MBR bootkit. Of course that this is mostly out of the window if at some point in the chain the trusted code just runs untrusted code, like the bootloader or the OS running unsigned code. Also the implementation is terrible, a proper implementation would allow the user to use their own certificates and only their own certificates, otherwise a compromised generic certificate fucks everything up like it already happened.

    • BCsven@lemmy.ca
      link
      fedilink
      arrow-up
      11
      ·
      2 days ago

      Secure boot is in case the OS gets tainted. It only allows a signed OS to boot.

      For example when new nvidia drivers are autocompiled into my Tumbleweed kernel during an update, on reboot the srcureboot asks if I want to view the new key or allow it. I then have to enter a password to add the key…otherwise it won’t boot with that kernel.

      • MonkeMischief@lemmy.today
        link
        fedilink
        arrow-up
        5
        ·
        1 day ago

        Woo, Tumbleweed! Their support of it is a pretty strong plus. I would get that screen sometimes too but it confused me a lot and I ended up just being like “Accept key I guess? Oh cool it boots.”

        What are you supposed to compare the key to? Nvidia’s repo on a website using a different device, or before you update or what? Is it like comparing checksums in Dolphin?

        I’m not particularly afraid of Evil Maids vs. my Tumbleweed desktop, as I’m much too poor for hired help (lol), so I just turned it off.

        They make compelling points about using it for laptops though.

        • BCsven@lemmy.ca
          link
          fedilink
          arrow-up
          4
          ·
          24 hours ago

          Yeah Tumbleweed supports a lot of things. Whenever people have complained about Linux not doing something, I’m like “Uh, OpenSUSE does”

          Since I’m updating the Kernel and nVidia driver modules, the system is making its own keypair, so I guess its not a check against a known supplied key but a machine specific key pair. Enrolling the key stores it to check against the kernel on boot.

          I suppose it protects against Random malware installs changing files, or if somebody swaps a drive on you.

          • MonkeMischief@lemmy.today
            link
            fedilink
            arrow-up
            1
            ·
            21 hours ago

            Right? OpenSUSE stopped my distrohopping way before I thought I would. I love it.

            Ahhh thank you, that makes a lot more sense! I don’t feel too at-risk on my desktop, but if I ever find myself having to take a laptop to like, DEF-CON, then sounds like it’d be pretty essential, along with full-disk-encryption, AppArmor/SElinux, and all those other “wildly inconvenient but more secure” protocols set up.😂 (Lmao that would be terrifying.)

            I might try to re-enable it just for the experience. After all, never know when some insane automated malware will hit the 'net that somehow exploits boot like that, and freaks out everyone who said “Nahh that’s not possible.”

      • hirihit640@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        11
        arrow-down
        1
        ·
        1 day ago

        disk encryption is much better with secure boot, because disk encryption requires a unencrypted partition, since the boot has to start somewhere unencrypted, and secure boot secures the unencrypted partition

        • spacegoat@lemmy.world
          link
          fedilink
          arrow-up
          6
          ·
          1 day ago

          After looking into it, you are correct and I was mistaken. Thanks for correcting my misinformation.

    • SomeLemmyUser@discuss.tchncs.de
      link
      fedilink
      arrow-up
      8
      ·
      2 days ago

      That’s exactly mz setup, as I need to leave my work laptop unauthorized in a shared space for prolonged periods.

      Can’t set up secure boot though because even fckin lenovo doesn’t provide the needed bios options for Linux nowadays -.-

      • ChaosMonkey@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        2
        ·
        1 day ago

        Which bios options do you need for that? Not enough to enter secure boot setup mode (restore factory keys) and enroll your keys?

        • SomeLemmyUser@discuss.tchncs.de
          link
          fedilink
          arrow-up
          1
          ·
          1 day ago

          Maybe I am not informed enough, i don’t exactly know if i missed something , but i did what i would do under microslop, I reset to factory keys I enable secure boot in user mode and I boot.

          When checking in the KDE security info, secure boot isn’t enabled.

          I asked lenovo support on how to do it (along with how to do an bios update under Debian) and the just replied there is no support for Linux. For either of those for my model and disabled the option to get support from a real human for my serial number.

          Maybe I would have needed to “enroll my keys”, I did not do that, mainly because I didn’t knew I needed to, and still dont know where to get my keys from and how to enroll them. Maybe you could enlighten me.

          Side rant: That I had to enter my full details including age and address and my serial number to even be able to get a support ticket is unbelievable imho

          My device isn’t included in the fwupd.

      • Auth@lemmy.world
        link
        fedilink
        English
        arrow-up
        10
        ·
        2 days ago

        They never said it did. Only that a laptop with encrypted drives is where secure boot makes sense. The OS can be as secure as it wants but if the drive isnt encrypted it can be accessed.

    • Billegh@lemmy.world
      link
      fedilink
      arrow-up
      175
      arrow-down
      1
      ·
      2 days ago

      I would disagree. The idea is great; eliminate preboot malware by trusting the whole boot stack. It has a place in computing and I would like to see it be something easier to work with.

      Pretty much everything about how it’s currently implemented is a mistake, I’ll agree with.

      • slacktoid@lemmy.ml
        link
        fedilink
        English
        arrow-up
        39
        arrow-down
        2
        ·
        2 days ago

        Microsoft has unofficial support for ext4 for their EFI partitions on their azure cloud, which in itself is a violation of their standard.

        • libewa@feddit.org
          link
          fedilink
          arrow-up
          21
          ·
          2 days ago

          UEFI doesn’t forbid you from implementing additional file systems, it just requires everyone to support UEFI-FAT. iBoot for example supports booting from HFS volumes.

                • libewa@feddit.org
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  11 hours ago

                  You are free to implement any filesystem driver, and either load it in your custom implementation of EFI, or from an EFI image stored on a FAT partition. The EfiFs project provides many drivers under a GPL, including exFAT, Btrfs, ext2-4, NTFS, ISO9660 (cdfs), ZFS and also HFS(+).

    • programmerlexi@sh.itjust.works
      link
      fedilink
      arrow-up
      3
      ·
      1 day ago

      My secure boot with hibernate works perfectly fine, or rather it did work fine before hibernate started freezing my system, secure boot or not.

      • jj4211@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        21 hours ago

        With Linux? Kernel signed with your own key to get out of lockdown mode restrictions?

        • programmerlexi@sh.itjust.works
          link
          fedilink
          arrow-up
          1
          ·
          20 hours ago

          There are no lockdown mode restrictions on my system. Kernel is not signed, but i switched to UKIs a couple months ago (hibernation worked fine with these).

          It is worth noting that the failure is hibernating, not resuming. Normally hibernate takes ~1 minute with fans spinning at max speed, but it recently started not finishing and instead being stuck on a black screen for more than 30 minutes without the fans running until i run out of patience (i hibernate before i go to sleep or head out) and force power off the system (power button 10 second press on my system).

    • muusemuuse@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      Alpine is dead simple if used for what’s it’s good at. The LBU is its best feature. It’s great on shitty ARM boards that digest SD cards. I use it on NUT servers throughout my network.

      • bridgeenjoyer@sh.itjust.works
        link
        fedilink
        arrow-up
        2
        ·
        1 day ago

        It was on an 08/ish laptop I wanted to just use for simple dvd watching and such. Had a lot of sound and disc issues. I’m a noob tho so went back to mint.

        • IpsumLauren@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          8 hours ago

          Same here, I run Mint everywhere I can, and the XFCE edition works especially well in old machines.

          Alpine is better suited for servers and especially containers, because the images can be really small. If you got enough RAM, there’s an installation mode that runs on it without writing to disk, pretty cool for systems where you want always to reboot in the same state.

  • Richard@lemmy.world
    link
    fedilink
    arrow-up
    16
    ·
    2 days ago

    Deciding to turn on secureboot on any distro that doesn’t support it out of the box is always a mistake.

    Still have nightmares from that one time i tried doing it under nixOS…

    • lightnsfw@reddthat.com
      link
      fedilink
      arrow-up
      1
      ·
      24 hours ago

      Yeah I tried doing it properly on my Bazzite install. It took exactly one round of Windows updates to bork it in a way that I couldn’t figure out how to fix. I had to start over.

        • h4lf8yte@lemmy.ml
          link
          fedilink
          arrow-up
          1
          ·
          6 hours ago

          Evil maid attacks. Trusted boot is necessary to prevent the modification of unencrypted boot code like bootloader + kernel + initrd. Modified boot code could potentially steal the master key for the root volume while it gets entered. Also rootkits that inject below the os.