3 ms·
Secure Boot is designed to help with malware compromising boot code that runs before the OS gets to run and thus has the ability to hide itself from OS and ever
by pilif 4y ago
Secure Boot is designed to help with malware compromising boot code that runs before the OS gets to run and thus has the ability to hide itself from OS and everything running on it while also able to intercept everything an OS is doing.
Given that often physical access allows secure boot to be turned off, it’s clearly not made to protect against a physical attacker.
Now, what’s left is a bit of a mixture of a political issue and developer laziness that makes secure boot a binary toggle of on=boots only microsoft-sanctioned OSes and off.
Ideally there was a safe way for a user to get their own boot loader and OSes signed to allow them to safely boot their own OS while still being sure that it was the user‘s intention to boot that thing.
Ironically, walled-garden Apple went exactly there with their secure boot implementation on their Apple Silicon macs (source: https://social.treehouse.systems/@marcan/109679905123512668 https://social.treehouse.systems/@marcan/109679905123512668)