• BCsven@lemmy.ca
    link
    fedilink
    arrow-up
    12
    ·
    4 days ago

    Secure boot is in case the OS gets tainted. It only allows a signed OS to boot.

    For example when new nvidia drivers are autocompiled into my Tumbleweed kernel during an update, on reboot the srcureboot asks if I want to view the new key or allow it. I then have to enter a password to add the key…otherwise it won’t boot with that kernel.

    • MonkeMischief@lemmy.today
      link
      fedilink
      arrow-up
      5
      ·
      4 days ago

      Woo, Tumbleweed! Their support of it is a pretty strong plus. I would get that screen sometimes too but it confused me a lot and I ended up just being like “Accept key I guess? Oh cool it boots.”

      What are you supposed to compare the key to? Nvidia’s repo on a website using a different device, or before you update or what? Is it like comparing checksums in Dolphin?

      I’m not particularly afraid of Evil Maids vs. my Tumbleweed desktop, as I’m much too poor for hired help (lol), so I just turned it off.

      They make compelling points about using it for laptops though.

      • BCsven@lemmy.ca
        link
        fedilink
        arrow-up
        4
        ·
        4 days ago

        Yeah Tumbleweed supports a lot of things. Whenever people have complained about Linux not doing something, I’m like “Uh, OpenSUSE does”

        Since I’m updating the Kernel and nVidia driver modules, the system is making its own keypair, so I guess its not a check against a known supplied key but a machine specific key pair. Enrolling the key stores it to check against the kernel on boot.

        I suppose it protects against Random malware installs changing files, or if somebody swaps a drive on you.

        • MonkeMischief@lemmy.today
          link
          fedilink
          arrow-up
          1
          ·
          4 days ago

          Right? OpenSUSE stopped my distrohopping way before I thought I would. I love it.

          Ahhh thank you, that makes a lot more sense! I don’t feel too at-risk on my desktop, but if I ever find myself having to take a laptop to like, DEF-CON, then sounds like it’d be pretty essential, along with full-disk-encryption, AppArmor/SElinux, and all those other “wildly inconvenient but more secure” protocols set up.😂 (Lmao that would be terrifying.)

          I might try to re-enable it just for the experience. After all, never know when some insane automated malware will hit the 'net that somehow exploits boot like that, and freaks out everyone who said “Nahh that’s not possible.”