4 ms·
Actually, yes, they did so also on (some) vendors' x86 firmware: https://www.omglinux.com/boot-linux-modern-lenovo-thinkpads-bios-setting/ https://www.omglinux.
by c0l0 3y ago
Actually, yes, they did so also on (some) vendors' x86 firmware: https://www.omglinux.com/boot-linux-modern-lenovo-thinkpads-bios-setting/ https://www.omglinux.com/boot-linux-modern-lenovo-thinkpads-...
These default firmware settings will prevent "third-party"-MSFT-signed EFI binaries from loading - gee, I wonder why that distinction is suddenly necessary, too? :)
In my view and experience, the threat model that Secure Boot and similar schemes to establishing a root of trust to assure that "noone (esp. not the owner) has tampered with this device" tries to protect against is VERY rarely relevant (to the owner of said device). The times that I have been inconvenienced or even prevented by that stuff from getting the software I, the owner of the device, want installed onto hardware that I paid good money for at a store/vendor have been numerous, however.