▲ 91 ▼ Microsoft's Secure Boot UEFI bootloader signing key expires in September, posing problems for Linux users (www.tomshardware.com) submitted 1 year ago by cm0002@programming.dev to c/linux@programming.dev 14 comments fedilink hide all child comments
[–] the_riviera_kid@lemmy.world 19 points 1 year ago (3 children) Not if you disable it, "secure boot" is a joke anyway. permalink fedilink source hideshow 6 child comments replies: [–] Badabinski@kbin.earth 27 points 1 year ago (3 children) I mean, Secure Boot does actually help defend against evil maid attacks if paired with FDE. Someone can't just fuck with your /boot (CVE-2016-4484 nonwithstanding) to do naughty things with your system if you have Secure Boot enabled. Does that fit with most people's threat model? I dunno, probably not. It does actually do something useful though. My work computer has it enabled and I feel better for it. The issue described in the article is easily dealt with if you just keep up with your firmware updates using fwupd. permalink fedilink source parent hideshow 6 child comments replies: [–] Maiq@lemy.lol 3 points 1 year ago Just so I have this right, fwupd will update the firmware with the new keys. Just fuzz on if you have to create a new secure-boot key yourself? permalink fedilink source parent [–] sylver_dragon@lemmy.world 1 point 1 year ago (1 child) Ya, Secure Boot is really only useful for corporate devices or very specific people who might actually be targeted by state level attackers. For most of us, it's not worth the hassle. permalink fedilink source parent hideshow 2 child comments replies: [–] noxypaws@pawb.social 4 points 1 year ago we are all currently being surveiled by state level attackers. permalink fedilink source parent [–] possiblylinux127@lemmy.zip 1 point 1 year ago It would be nice if system76 did firmware updates via fwup It doesn't nor does it protect against tampering what so ever permalink fedilink source parent [–] possiblylinux127@lemmy.zip 3 points 1 year ago It can be a major security benefit when done correctly. I'm not sure if there is a single vendor doing it correctly permalink fedilink source parent [–] Prime@lemmy.sdf.org 0 points 1 year ago Cannot always be disabled permalink fedilink source parent
[–] Badabinski@kbin.earth 27 points 1 year ago (3 children) I mean, Secure Boot does actually help defend against evil maid attacks if paired with FDE. Someone can't just fuck with your /boot (CVE-2016-4484 nonwithstanding) to do naughty things with your system if you have Secure Boot enabled. Does that fit with most people's threat model? I dunno, probably not. It does actually do something useful though. My work computer has it enabled and I feel better for it. The issue described in the article is easily dealt with if you just keep up with your firmware updates using fwupd. permalink fedilink source parent hideshow 6 child comments replies: [–] Maiq@lemy.lol 3 points 1 year ago Just so I have this right, fwupd will update the firmware with the new keys. Just fuzz on if you have to create a new secure-boot key yourself? permalink fedilink source parent [–] sylver_dragon@lemmy.world 1 point 1 year ago (1 child) Ya, Secure Boot is really only useful for corporate devices or very specific people who might actually be targeted by state level attackers. For most of us, it's not worth the hassle. permalink fedilink source parent hideshow 2 child comments replies: [–] noxypaws@pawb.social 4 points 1 year ago we are all currently being surveiled by state level attackers. permalink fedilink source parent [–] possiblylinux127@lemmy.zip 1 point 1 year ago It would be nice if system76 did firmware updates via fwup It doesn't nor does it protect against tampering what so ever permalink fedilink source parent
[–] Maiq@lemy.lol 3 points 1 year ago Just so I have this right, fwupd will update the firmware with the new keys. Just fuzz on if you have to create a new secure-boot key yourself? permalink fedilink source parent
[–] sylver_dragon@lemmy.world 1 point 1 year ago (1 child) Ya, Secure Boot is really only useful for corporate devices or very specific people who might actually be targeted by state level attackers. For most of us, it's not worth the hassle. permalink fedilink source parent hideshow 2 child comments replies: [–] noxypaws@pawb.social 4 points 1 year ago we are all currently being surveiled by state level attackers. permalink fedilink source parent
[–] noxypaws@pawb.social 4 points 1 year ago we are all currently being surveiled by state level attackers. permalink fedilink source parent
[–] possiblylinux127@lemmy.zip 1 point 1 year ago It would be nice if system76 did firmware updates via fwup It doesn't nor does it protect against tampering what so ever permalink fedilink source parent
[–] possiblylinux127@lemmy.zip 3 points 1 year ago It can be a major security benefit when done correctly. I'm not sure if there is a single vendor doing it correctly permalink fedilink source parent
[–] Prime@lemmy.sdf.org 0 points 1 year ago Cannot always be disabled permalink fedilink source parent