4 ms·
UEFI and "Secure Boot" has always stuck me as a terrible idea. It adds lots of complexity to the boot process - which means that it adds vulnerabilities. Added
by jgaa 4y ago
UEFI and "Secure Boot" has always stuck me as a terrible idea. It adds lots of complexity to the boot process - which means that it adds vulnerabilities. Added complexity almost always leads to more vulnerabilities.
It adds a DOS partition (!!!) to the disk, and prevents me from for example dual booting two versions of Debian on the same machine.
The whole thing has a bad smell of Microsoft around it, which translates to hidden motives (make it hard to not run Microsoft on this hardware) and insecurity (because they don't do "secure". They never did).
If you want "secure boot" - get hardware that support "legacy boot" and boot something else than Microsoft Windows ;)
- vetinari 4y ago> It adds a DOS partition (!!!) to the disk, It is a FAT32 partition; most DOS versions are unable to read it. > prevents me from for example dual booting two versions of Debian on the same machine. It doesn't; UEFI doesn't care what is the boot image, only that there is some. You can register as many boot targets as you want. Check efibootmgr in one of your debian instances, if your installer is not capable of doing that.
- deleted 4y ago[deleted]
- boring_twenties 4y ago> prevents me from for example dual booting two versions of Debian on the same machine. It absolutely does not.