4 ms·
> Secure Boot on most Linux distributions, except for a few that implement TPM-based Secure Boot like ChromeOS Flex and custom Linux builds, is merely intended
by coastal73 2y ago
> Secure Boot on most Linux distributions, except for a few that implement TPM-based Secure Boot like ChromeOS Flex and custom Linux builds, is merely intended for UEFI support and Windows dual-boot compatibility, rather than being a genuine mechanism for detecting OS image tampering.
So basically Linux distros without DM-Verity and TPM support? Basically not boot chain verified?
ChromeOS uses coreboot vboot and Flex may use secure boot, but I haven't seen a ChromiumOS fork signed to work with UEFI secure boot, or worse coreboot with vboot, while a Linux distro it's possible with secure boot (I'm not sure about vboot), but to secure it and the software to a similar level, I feel it would just become similar to ChromiumOS, because there's so much software on Linux that is not isolated. I think Flatpak has way too many permissive permissions that even allow access to home directory and system permissions by default. Android apps are better, albeit ChromiumOS doesn't have Android apps enabled, are built with memory safe Java/Kotlin, with denied by default permissions.
QubesOS does isolate Linux applications better than ChromiumOS, but it's just because you can have multiple virtual machines to isolate each Linux application. AFAIK ChromiumOS just uses one virtual machine + container?
It is technically possible to apply DM-Verity but I've only had experience setting it up via initramfs, I heard Android applies it directly from the kernel. Making DM-Verity work on a lot of distros would completely change the way traditional Linux works, and would ideally require something similar to Android and ChromeOS way of working by system updates, to apply those root images. (Or maybe remake a root image, but I want to reduce privilege as much as possible.)
And not just that, traditional Linux out of the gate lets the end-user use root, or a privilege escalation software like sudo/doas, whereas Android/ChromeOS has no root access by default.