3 ms·
> Secure Boot doesn't build a walled garden if implemented the way it generally is on x86: anyone physically present at boot time can add and remove keys or ju
by Perseids 12y ago
> Secure Boot doesn't build a walled garden if implemented the way it generally is on x86: anyone physically present at boot time can add and remove keys or just disable it
That is true for very competent end users, but near impossible for the general masses.
We have come so far as to be able to install big Linux distributions like Fedora and Ubuntu without any hassle on Secure Boot systems. That only works though, because their bootloader, kernel and kernel modules were blessed (i.e. signed) by the distributor. Building your own kernel still requires you to disable Secure Boot (or far more difficult, add your own key to Secure Boot and sign everything yourself). Heck, even ZFS, which is otherwise as easy to install as adding a third party repository, is incompatible with secure boot, as it loads a custom kernel module.
Now, to visualize the real world difficulty of disabling secure boot imagine guiding your spouse or friend through this process over the phone: Reboot the system a few times until they found the text telling which key press during boot to enter EFI setup or guess correctly for their hardware manufacturer, let them read out aloud what they see - possibly in a language they don't speak well if the interface is not localized, navigate them through the menus, find out how to change the Secure Boot setting (one should think switching binary settings and moving stuff up and down in a list would be a solved UI problem nowadays… speaking from experience with my HP Probook UEFI interface, it is not, though), (if you are particularly unlucky: explain which keys of their keyboard layout map to the needed US keyboard layout), exit and safe the settings.