5 ms·
If Linux users had "stepped up to the plate" and demanded their own separate PKI, nothing would be different, except that every system that shipped with Windows
by trelane 1y ago
If Linux users had "stepped up to the plate" and demanded their own separate PKI, nothing would be different, except that every system that shipped with Windows would be locked to Windows. Dual booting would not be a thing.
I mean, your statement is self contradictory. Linux users demanded no signing etc. So, had the industry listened to Linux users, there would be no signing. We do not live in that universe.
There are some vendors that don't have secureboot. They are e.g. System76. You can enable your own SecureBoot if you want[1], though some things may not work, like checking GPU firmware signatures, because they are signed by Microsoft only (there are other issues, depending on how deeply Microsoft is assumed in your system, see e.g
"On some devices, removing either of these keys could disable all video output.")
[1] https://wiki.gentoo.org/wiki/Secure_Boot https://wiki.gentoo.org/wiki/Secure_Boot
- sugarpimpdorsey 1y agoThis makes no sense. Microsoft uses separate CAs (read: separate root certificates) to sign Windows vs Linux bootloaders. Both CAs have to be trusted. They could also, in theory, be revoked separately. There is no reason the "third party" CA couldn't be run by Red Hat. It's done by MS out of convenience.