4 ms·
All WoA (Windows 10/11 on ARM) devices based on the Qualcomm Snapdragon 7/8cx Gen 3 seem to allow disabling UEFI SecureBoot, AFAIK earlier SoCs did as well. Op
by brynet 3y ago
All WoA (Windows 10/11 on ARM) devices based on the Qualcomm Snapdragon 7/8cx Gen 3 seem to allow disabling UEFI SecureBoot, AFAIK earlier SoCs did as well.
OpenBSD/arm64 runs on the Microsoft Dev Kit 2023 and Lenovo ThinkPad x13s machines, out of the box. OpenBSD supported booting/installing on these even before Linux, although Linux support has improved.
https://www.openbsd.org/arm64.html https://www.openbsd.org/arm64.html
- Gazoche 3y agoThat's good news, as long as disabling Secure Boot doesn't put your device in a "no fun allowed" zone where it's cut off from banking, Netflix, etc. Like SafetyNet on Android.
- brynet 3y agoI'm not aware of anything that depends on the SecureBoot status of a device, except possibly Widevine DRM for video streaming, but I don't see how that would be unique to ARM, disabling SecureBoot is also usually required on x86 for running alternative OSes without Microsoft's signed shim bootloader. There is no Widevine support for OpenBSD anyway, so it's never been possible to watch Netflix. Fortunately, there are solutions for that... Incidentally, Fedora Asahi Linux for Apple Silicon (ARM) got Widevine (hence, Netflix) working without any form of SecureBoot, they wrote about it recently on their blog.
- NekkoDroid 3y agoOne thing I know is the most invasive anti-cheat of them all: Vanguard. When you are running Windows 11 it requires secure boot to be enabled (IIRC this isn't the case for when running Windows 10). On a different note, I actually learned a bit ago, that setting up secure boot with your own keys is not too hard if you are running a UKI, with only needing to sign systemd-boot and the kernel.
- vetinari 3y agoWith your own keys, you mean adding your MOK (machine owner key), or going the entire way, with the Microsoft ones removed? The first one is easy, the second one seems to be more complicated, especially if you have Option ROMs signed by the keys you would like to remove.
- NekkoDroid 3y agoI mostly just let `sbctl` do its stuff automatically, but I do manually enroll my own keys and the Microsoft keys (when in Setup Mode), since they apparently might be required for some things to work correctly.