4 ms·
Whats the issue with Secure Boot? That's an actually good idea security wise.
by dtx1 2y ago
Whats the issue with Secure Boot? That's an actually good idea security wise.
- Am4TIfIsER0ppos 2y agoNo it isn't. It is allowing microsoft the only authority to allow you to run software of your choice on your own hardware.
- raxxorraxor 2y agoNah. While ensuring the integrity of your boot partition can be a security benefit, it isn't really the most attractive target for malware anymore. And instead most use cases are levelled against you. For example some computer games now require Windows 11 and secure boot to be enabled for remote attestation. If the mechanism becomes more pervasive, we will see more of that. That is very likely the main motivation of Microsoft here as well. And while there are enough methods for device identification and fingerprinting, I don't want my device to be cooperative here. I do not have evil maids either and the whole trusted computing stuff is badly designed, intransparent and mostly security fluff. I do understand the security benefit for enterprises and disk encryption, but I use alternatives for security. Also Microsoft defacto has control about allowed and allegedly secure distributions. Yes, you can add your own key, but that will probably be as viable as running your own CA at some point. Overall it just makes open computing more complicated and the security gain is negligible. edit: No idea why you were downvoted. Many believe trusted computing to "just" increase security. But the intentions and mechanisms behind that aren't as neutral as some would like you to believe. There are also other fights like AMD Pluton, which really lowers the desirability of AMD hardware for me. I though they could have been an alternative for Intel, which is fairly needed. But their developments aren't attractive if they invest in such technologies. I also forgot that a TPM has an endorsement key that is used as a hardware ID. It cannot be changed by the user. The whole setup is a scam and scams are a security threat. Secure boot and trusted computing should die, there are better ways to secure system integrity.
- guappa 2y agoIf you can tell me how to put your own public key in there, without spending hours on google; I will agree that it is a good idea security wise.