3 ms·
I'm sure this is a naive take, but why is it not possible to enter a new key into the BIOS (dating myself, I know it's EFI) by hand?
by omnibrain 1y ago
I'm sure this is a naive take, but why is it not possible to enter a new key into the BIOS (dating myself, I know it's EFI) by hand?
- nottorp 1y agoYou'd have control over what boots on your computer then...
- ozgrakkurt 1y agoThat would be a disaster. Or imagine what would happen if you just disabled secure boot, your computer will be infected with viruses and your bank account emptied instantly I reckon
- Dead_Lemon 1y agoSecure boot doesn't stop user-space malicious activity. I'd argue that it only helps check a tick box on corporate security manifest, as it indicates the kernel being booted, is not tampered with.
- OldfieldFund 1y agoOP was being sarcastic
- nicman23 1y agoyou literally have though. you can self sign everything and set up uefi to only boot your signature
- const_cast 1y agoOnly on x86 secure boot implementations. On most devices with trusted boot, you don't have this option.
- nicman23 1y agouefi on non x86 is a non starter for most people anyways. not that uboot is better
- nicman23 1y agoit is
- jcgl 1y agoIt should be, at least on higher-end boards, no?
- eqvinox 1y agoIt's possible and it's what you should be doing. "sbctl" (https://github.com/Foxboron/sbctl https://github.com/Foxboron/sbctl) AFAIK has a reasonable frontend for doing that on Linux (don't know, I did it manually). You have to put the system in "secure boot setup mode" in BIOS/UEFI options before booting, which enables changing the PK (Platform Key) which is used to chain off all the other keys. (Setup mode should be automatically exited when you install a new PK.) You can keep the Microsoft keys in there if you want to dual boot Windows, you just need to re-sign the keys themselves with your own PK.