4 ms·
Can you elaborate?
by firebaze 4y ago
Can you elaborate?
- deleted 4y ago[deleted]
- ianlevesque 4y agoThey’re not wrong. This is the code signing of your bootloader, kernel, etc that would prevent for example someone tampering with your boot partition to silently capture your encryption password the next time you type it in at boot. It’s a real threat but not one I’m concerned about. I have no idea if Pop OS not doing this is a regression from upstream Ubuntu or not.
- als0 4y agoLast time I tried, you had to disable UEFI secure boot to get PopOS to start. And then follow some complex steps to self sign all those components. Regular Ubuntu (and Debian) does not need any of this.
- deleted 4y ago[deleted]
- joebiden2 4y agoThe reason "secure boot" (yeah, scare quotes intended) is not the default for linux distributions: > The boot loader and kernel must be signed with a trusted key recognized by the UEFI firmware. Microsoft maintains a widely trusted key for Secure Boot called the Microsoft UEFI Certificate Authority, and many Linux distributions use it to sign their boot loaders and kernels. This enables them to boot on systems with Secure Boot enabled by default.