Evil maid attacks. Trusted boot is necessary to prevent the modification of unencrypted boot code like bootloader + kernel + initrd. Modified boot code could potentially steal the master key for the root volume while it gets entered. Also rootkits that inject below the os.
Yeah I tried doing it properly on my Bazzite install. It took exactly one round of Windows updates to bork it in a way that I couldn’t figure out how to fix. I had to start over.
I will just never bother with any of this Secure boot nonsense. I leave that bs to the windows users.
Sadly it is actually one of the biggest security features that modern computers have
What kind of attack does it actually protect against?
Evil maid attacks. Trusted boot is necessary to prevent the modification of unencrypted boot code like bootloader + kernel + initrd. Modified boot code could potentially steal the master key for the root volume while it gets entered. Also rootkits that inject below the os.
Rootkits
Yeah I tried doing it properly on my Bazzite install. It took exactly one round of Windows updates to bork it in a way that I couldn’t figure out how to fix. I had to start over.