• h4lf8yte@lemmy.ml
          link
          fedilink
          arrow-up
          3
          ·
          4 days ago

          Evil maid attacks. Trusted boot is necessary to prevent the modification of unencrypted boot code like bootloader + kernel + initrd. Modified boot code could potentially steal the master key for the root volume while it gets entered. Also rootkits that inject below the os.

    • lightnsfw@reddthat.com
      link
      fedilink
      arrow-up
      1
      ·
      5 days ago

      Yeah I tried doing it properly on my Bazzite install. It took exactly one round of Windows updates to bork it in a way that I couldn’t figure out how to fix. I had to start over.