3 ms·
Wired is selectively quoting and interpreting. Linus is talking in generalities and unfortunately that means he's missing the specific, immediate problem that a
by pslam 14y ago
Wired is selectively quoting and interpreting. Linus is talking in generalities and unfortunately that means he's missing the specific, immediate problem that a lot of people are going to face.
Secure Boot in itself isn't necessarily a problem, and is a good thing in that it can actually increase security. However, if you don't have the ability to install your own certificate (or get a leaf cert), then it completely prevents you from installing your own OS. If a PC comes with only Microsoft's cert installed, then you can only install Microsoft software.
If the OS refuses to boot when you disable Secure Boot, then you can't dual boot the pre-installed OS, and it takes a lot of effort to get things working again. Plus, you lose Secure Boot for both OS's.
This is all a stupid mess which could have been solved by allowing users to install their own certificates - and I don't mean the Fedora solution of also having their cert installed and then handing Fedora a lot of money for a leaf.
- cooldeal 14y ago>If the OS refuses to boot when you disable Secure Boot, then you can't dual boot the pre-installed OS, and it takes a lot of effort to get things working again. What? Which OS refuses to boot when you disable Secure Boot? >This is all a stupid mess which could have been solved by allowing users to install their own certificates Exactly which UEFI Secure Boot does. Here's a guide. http://blog.hansenpartnership.com/owning-your-windows-8-uefi-platform/ http://blog.hansenpartnership.com/owning-your-windows-8-uefi...
- pslam 14y ago> What? Which OS refuses to boot when you disable Secure Boot? The one which was installed with secure boot enabled. My reading is the OS will prevent forward progress when it notices secure boot was bypassed when it expected it to be on. Never tried this myself - I'm likely misinformed. > Exactly which UEFI Secure Boot does. And apparently optional, and not something every machine implements, which was the subject of a LOT of stories a year back. Did this ever get resolved as being mandatory, and/or did all UEFI providers figure it was best practice in the end?