6 ms·
you can always either disable secureboot and driver signature verification, or (the better solution) just enroll your own certificate in your TPM and sign the d
by dark-star 6mo ago
you can always either disable secureboot and driver signature verification, or (the better solution) just enroll your own certificate in your TPM and sign the driver with that...
- malfist 6mo ago> or (the better solution) just enroll your own certificate in your TPM and sign the driver with that... I'll tell Grandma that's what she needs to do.
- pixel_popping 6mo agoMake sure that she setup a PKI infrastructure to manage certificate revocation as well, wouldn't want a bad grandson to mess with it.
- p_ing 6mo agoWhy would you put Grandma on VeriCrypt in the first place? It's the more 'difficult' option for FDE.
- unethical_ban 6mo agoWhat's easier, and bitlocker doesn't count. I want my FDE to be based on a password or a keyfile, not simply by some code in the motherboard. I want it encrypted until I, the operator, provide some data to unlock. In my limited experience with bitlocker, the disk is decryptable automatically as long as it's in the original motherboard.
- p_ing 6mo ago> and bitlocker doesn't count. Wat? Bitlocker is the answer to your question. > In my limited experience with bitlocker, the disk is decryptable automatically as long as it's in the original motherboard. It's unlocked (not decrypted) when the OS boots, yes. You can optionally enforce (not on Home) other unlock methods, such as PIN before the OS boots. > I want my FDE to be based on a password or a keyfile, not simply by some code in the motherboard. That's less secure than TPM.
- unethical_ban 6mo agoIf someone steals my laptop, and there is no factor of decryption requiring something I possess or know, then the only use of that disk being encrypted is that I can throw it out more safely at end of life. Thieves/LEO has the data because they have the motherboard. If bitlocker has a PIN/passphrase decrypt option, then I missed it.
- p_ing 6mo agoWhile a thief or LEO could boot the OS, just having the motherboard doesn’t give them access to the underlying data. They would need to have a valid user account.
- dark-star 6mo agoyou should protect your account with a password of course. that will be used to decrypt your drive/data
- unethical_ban 6mo agoIt was not made clear to me that my username/password was the decryption method! I was expecting something like Linux where a separate password is needed. Furthermore it wasn't intuitive to me that my user account would decrypt more than just my home directory.
- dark-star 6mo agoyour grandma is probably fine with BitLocker....
- askonomm 6mo agoAh, yes, the [insert super inconvenient and complex thing to do that most people don’t know, want or should do] will solve it! And when that fails, surely the user can just write their own OS, right? Bunch of skill-issued complainers we the users are.
- falcor84 6mo agoWell, the hope was always that those of us inconvenienced by M$ would all collectively contribute to making Linux distros more convenient for everyone. But we can't ever seem to get inconvenienced enough to actually sufficiently mobilize and/or coordinate such an effort.
- weaksauce 6mo agoIt does seem like linux is having its moment right now. there's the money and effort valve is putting into KDE making the steamdeck and steammachine polished for their hardware which helps all users of KDE. cachyos is making having a rolling distro really smooth and snappy on old hardware and making games work mostly ootb. stuff like winboat and wine will let you use the few windows apps you need. you are kinda stuck though if you want to use something like fusion360 or solidworks. freecad has improved quite a bit but it's still like gimp where it's slightly worse UX in a lot of ways.
- SV_BubbleTime 6mo agoValve is doing great work. Now… maybe we could condense the 10,000 pointless distros down to a dozen? Oops, nope. Now 10,001, except this one has the menu bar in the middle of the screen and it moves around.
- account42 6mo agoThe distros are not pointless. For every one of them there was a human being that wanted something to work differently and the nature of open source let them do it. That should be celebrated and the day we loose that flexibility would be a very sad day.
- ntoskrnl_exe 6mo agoAnd they say Linux is inconvenient because you have to open the terminal every once in a while.