4 ms·
You've missed the point. If they are enabled by default or display a message elsewhere is irrelevant, the fact is they don't display a watermark when the user i
by Tomdarkness 13y ago
You've missed the point. If they are enabled by default or display a message elsewhere is irrelevant, the fact is they don't display a watermark when the user is using the less secure option. Also I specifically referred to the built-in administrator which is not like a normal administrator account as everything it executes has elevated privileges.
Yes, all of those have nothing to do directly with the boot sequence. But again, that is not the point. They all help prevent the malware from executing or gaining hold in the first place, before it has the chance to compromise the boot sequence. Secure boot does nothing to stop the malware in the first instance, just prevents it from messing with anything at boot. In my view, I'd say that actively defending from the malware is far better than reacting after the event to limit the impact. I'm not saying secure boot is not helpful but rather the current level of notification you get when it is disabled is disproportionate.
- ksk 13y agoOK, too many loose ends here. Let me tie it up.. All those settings are controlled from inside the OS. The OS can track whether the user has intentionally changed them. Secure boot has to be enabled outside the OS. In which case the OS has no way of knowing whether the user has intentionally disabled it. Assuming the worst-case scenario can be a good thing when it comes to security. Personally, unless I can get it to work with CentOS, I wont be using Secure Boot since I ship products on Linux. However, I don't think the warning is disproportionate.